I have two event start event having extracted fields from log managerid ,branch I'd,empname using index = emp source = empsource " offer letters"
End event having extracted field empid,branch id index= manager source= manager source " relieving letters"
I want to get empid who's is taken offer letter and relieving later and duration.
Hi @Sekhar,
let me understand, you can correlate events using the id field or there some other corrrelation rule?
if you can use id to correlate events, you could try something like this:
(index=emp source=empsource " offer letters") OR (index=manager source=manager source " relieving letters")
| stats
earliest(_time) AS earliest
latest(_time) AS latest
values(branch) AS branch
values(managerid) AS managerid
values(empname) AS empname
BY id
| eval diff =latest-earliest,
| eval earliest=strftime(earliest,"%Y-%m-%d %H:%M:%S"), latest=strftime(latest,"%Y-%m-%d %H:%M:%S")Ciao.
Giuseppe