Not totally clear what the eventstats is doing here. It would help if you could illustrate the desired results from mock data. Do you mean to produce two tables like these? 1. superhero archet...
See more...
Not totally clear what the eventstats is doing here. It would help if you could illustrate the desired results from mock data. Do you mean to produce two tables like these? 1. superhero archetype id strengths superhero superman super strength, flight, and heat vision superhero batman exceptional martial arts skills, detective abilities, and psychic abilities 2. villan archetype id strengths villain joker cunning and unpredictable personality To do these, you can use index=characters
| spath path={}
| mvexpand {}
| spath input={}
| fields id, strengths, archetype
| where archetype="superhero"
| stats values(*) as * by id for superhero; for villan, use index=characters
```
| spath path={}
| mvexpand {}
| spath input={}
| fields id, strengths, archetype
| where archetype="villan"
| stats values(*) as * by id Here is an emulation for you to play with and compare with real data | makeresults
| eval _raw="[
{
\"id\": \"superman\",
\"strengths\": \"super strength, flight, and heat vision\",
\"archetype\": \"superhero\"
},
{
\"id\": \"batman\",
\"strengths\": \"exceptional martial arts skills, detective abilities, and psychic abilities\",
\"archetype\": \"superhero\"
},
{
\"id\": \"joker\",
\"strengths\": \"cunning and unpredictable personality\",
\"archetype\": \"villain\"
}
]"
| spath
``` the above emulates
index=characters
```