Hi everyone, I'm trying to get the following search work, but for some reason I'm doing something wrong:
inputlookup events_lookup
| eval key = _key
|search key in
[| inputlookup notable_events_lookup search name="tobedeleted" | fields - _time | fields event_id]
|table key
I'm basically trying to import event_id from a lookup ( notable_events_lookup) which is matching to another lookup (evets_lookup) in order to remove the matching event in the lookup (events_lookup)
I hope it makes sense what I'm trying to explain. Thanks everyone
try this
inputlookup events_lookup
| eval key = _key
| search [| inputlookup notable_events_lookup search name="tobedeleted" | fields - _time | rename event_id as key | fields key]
|table key
try this
inputlookup events_lookup
| eval key = _key
| search [| inputlookup notable_events_lookup search name="tobedeleted" | fields - _time | rename event_id as key | fields key]
|table key
Hi @aasabatini
I have the below SPL: -
| inputlookup table1.csv where index="xxx" | fields index, host
| search NOT [search index="xxx" | dedup host | table index, host]
I have table2.csv with following fields: -
index, host, lastTime
I need to search the results from above SPL based on host and index in table2.csv and get the corresponding value of the column: lastTime. Thus, as the final resultset, I need: - index, host, lastTime.
Please help with your suggestions.
Thank you
Thanks a lot! it works 🙂