Let's say I have a multivalue fieldA and a fieldB. I know you can do something like "| where field=value" in a search or just have it in the first part of the search arguments, but is it possible to do something for where I use all returned values part of fieldA as the search for fieldB?
Are you looking for a subsearch so that your main search will look for fieldB="any of field A" values?
index=bla... [
search index=find_values_of_fieldA
| stats values(fieldA) as fieldB
| format ]
Are you looking for a subsearch so that your main search will look for fieldB="any of field A" values?
index=bla... [
search index=find_values_of_fieldA
| stats values(fieldA) as fieldB
| format ]
|mvexpand fieldA
|mvexpand fieldB
|eval flag=if(match(fieldA ,fieldB),1,0)
OR
|mvexpand fieldA
|mvexpand fieldB
|eval flag=if(match(fieldB ,fieldA),1,0)