Hi all, I need your help in validating my query. Please help..
in indexA , fields are: user, login (user=firstname, login=login_id) in indexB , fields are: userName, city (city: location of the ...
See more...
Hi all, I need your help in validating my query. Please help..
in indexA , fields are: user, login (user=firstname, login=login_id) in indexB , fields are: userName, city (city: location of the employee, userName:firstname comma lastname)
I have userName in indexA but it was not extracted under any field name. So I am extracting this field and based on that userName combination, I need to get location of that employee. I am trying with the below query, but it is not giving location detail. Location is emplty for all rows
(index=indexA sourcetype="A" user=*) OR (index=indexB sourcetype="B" userName=*)
| rex field=_raw "user=(?<userName>[^.]*)\s+cat"
| fields userName city login
| stats count as events values(city) as city by userName login
eg:user=aaa, login=aabb city=xyz, userName=aaa, bbb
with my query I have to get result as
userName
login
events
city
aaa, bbb
aabb
1
xyz
But Iam getting empty in city. please help.. Thanks