I have a requirement where..
My first query is as below:
index = <my_index> eventtype=" " | table field1
And the values of my first query has to be used in the search of my second query
index=<my_index> source= " " and field1 values..
I tried using join it doesnt seem to help.
hi use fields comand not table, also if the result of the first search are less number of events you can use a subsearch.
index=<my_index> [search index = <my_index> eventtype=" " | fields field1]