We have logs in two different indexes. There is no common field other than the _time . The timestamp of the events in second index is about 5 seconds further than the events in the first index. How do in I need to join these two indexes based on the date and the hour and try to match inside of minute?
Thanks,
If you only have a common field of _time, are you planning on visual matching and how are you looking to match things inside that minute?
You can also use stats to 'join' data together, but perhaps you can expand on your use case with an example so we can give more useful help.
You can try to align the _time field with bin command and then match events by exactly the same value of that field (you can leave the original value for reference of course).
Or you can use the transaction command (generally, transaction should be avoided since it's relatively resource intensive and has its limitations but sometimes it's the only reasonable solution).