I'm getting some strange results with the map command. This is what I need to do... in one index (1st search) I have 'action' , 'host', and 'time' field. The other search (2nd search) is used in the map using fields 'user' and 'time'. I need to extract the field 'user' where the '_time' fields are very close together (few minutes) in both indexes. My result when I run the search I get duplicate rows and more events. Thanks for your help.