I want to join with search results and correlate to the specific event. Trying _cd field, but it doesn't appear to return any values.
index=main * | join _cd [search *]
I was expecting to see some bucket and address values?
earliest="-1s" * | rex field=_cd "(?<bucket>d+):(?<address>d+)"
try following these link below: