I wanted to reconcile the data from 2 indexes say index=A and index=B both indexes have some common fileds like field1,field2,field3,field4,field5
at the end I wanted to compare the data from index A and index B side by side with time span of 1s.
The report should display _time index1 index2 source field1 field2 field3 field4 field5 and difference between the 2 indexes eventcount or any other.
@inventsekar Do you have any examples/sample search to share for my requirement.
hi @inventsekar , Thanks for your response. For now it's a one time report. I'm looking for a sample search to accomplish this.
we have about ~ 3-5K events per day