Try this (avoid using subsearch
😞
(index=indexA sourcetype=srcTypeA Network_Address="1.1.1.1") OR (index=indexB "stringExample") | stats dc(index) AS indexCount values(*) AS * by user | where indexCount=1 AND index="indexA" | fields user src time
Keep in mind that by discluding ALL user
s from index=indexB
you are also discluding all events
( fields
) from index=indexB
so much of your question is nonsensical!
No need to pipe to subsearch:
index=A sourcetype=srcTypeA Network_Address="1.1.1.1" NOT [search index=B "stringExample" | fields user] | stats values(src) AS srvIP values(time) AS time by user
Try this (avoid using subsearch
😞
(index=indexA sourcetype=srcTypeA Network_Address="1.1.1.1") OR (index=indexB "stringExample") | stats dc(index) AS indexCount values(*) AS * by user | where indexCount=1 AND index="indexA" | fields user src time
Keep in mind that by discluding ALL user
s from index=indexB
you are also discluding all events
( fields
) from index=indexB
so much of your question is nonsensical!