Hi,
I have database table and anomaly table. Both tables have a field database_id. Now I am interested in the status and confidence fields in anomaly table as well as data_source and ip fields in database table. I want to combine them into one table based on the database_id. I tried some queries like below but its result was not as expected.
index=anomalies | JOIN type=left database_id [SEARCH index=assets] | fields anomaly_id, confidence, current_status, database_id, source_type, ip
How could I write a query that returns a table showing the info for all anomalies as well as the database info related to that anomaly using database_id as a bridge?
Thank you in advance!
Regards,
In what way were they not as expected?
Seems like it works for now! Thank you!