within an index i have Records with a Name and Id and some with just the ID.
sourcetype=A Name="Foo" Id=23
sourcetype=A Name="Blah" Id=24
sourcetype=B Id = 24 Message="Found"
sourcetype=B Id =23 Message="Lost"
sourcetype=B Id=24 Message="Lost"
I am looking to query and get
Name="Foo" Id=23 Message="Lost"
Name="Blah" Id=24 Message="Found"
Name="Blah" Id=24 Message="Lost"
basically wanting to use source a as a lookup i have tried join the syntaxes but no luck
Try like this
sourcetype=A OR sourcetype=B | stats values(Name) as Name values(Message) as Message by Id