There are two sourcetypes ,
sourcetype=A sourcetype=B and we have extracted a field "login" in both sourcetypes
1. we need to have a "count" of the login values which are available in sourcetype=A but not in sourcetype=B
2. we need to have a "list of values" of the login values which are available in sourcetype=A but not in sourcetype=B
3. Any Graph that we can show the these many "login" are missing in compare with sourcetypes using timechart? - any suggestions?
sourcetype="A" OR sourcetype="B"
| eval sourcetypeA=if(sourcetype="A",sourcetype,null)
| eval sourcetypeB=if(sourcetype="B",sourcetype,null)
| stats values(sourcetypeA) as sourcetypeA values(sourcetypeB) as sourcetypeB by login
| where sourcetypeA="A" and isnull(sourcetypeB)
| stats count