Hi All,
I have two source type , for example.
1) sourcetype 1
2) sourcetype 2
In sourcetype 1 I have a string which I have queried from a search and I need to search if this string is present in sourcetype2 which is present as a list.
example of the string in sourcetype1.
RHEL-2007:0103
I need to search the above string in Sourcetype2 which is present as a list in dictionary format, example as below.
errata: [ [-]
A
B
C
D
E
F
]
Can somebody please help.
index=... sourcetype = 1 OR sourcetype = 2 | stats dc(sourcetype) AS stc by errata | where stc == 2
OR
index=... sourcetype = 2 [ |inputlookup errata |format]
What is the output of your first search?