Query1-Results:
ProxiesProcessed,Status
Query2-Results:
ProxiesProcessed,Audio_Tracks,year_mm_dd
Join Query:
index=index1
host=node1
source="results.log"
"item: " AND "valid_audio_path: " |eval ProxiesProcessed=trim(substr(_raw,101,11)) | dedup ProxiesProcessed |rename ProxiesProcessed as P_ProxiesProcessed
|eval Audio_Tracks = trim(substr(_raw,130,len(_raw)-129))
|eval year_mm_dd = trim(substr(Audio_Tracks,36,07))
|fields P_ProxiesProcessed,Audio_Tracks,year_mm_dd
|join type=left max=0 P_ProxiesProcessed
[search index=index1 host=node1 source="results.log"
"Item Processed :: "
|eval ProxiesProcessed=trim(substr(_raw,112,10))
|eval Status=trim(substr(_raw,144,len(_raw)-143))
|dedup ProxiesProcessed
|where Status="already_transcoded"
|fields ProxiesProcessed,Status
|rename ProxiesProcessed as P_ProxiesProcessed
|rename Status as S_Status ]
|table P_ProxiesProcessed,Audio_Tracks,year_mm_dd,S_Status
I'm trying to join with the ProxiesProcessed field to get matching results with Query1 & Query2
If I execute the Query1 (used in subsearch) separately, gives me 300 events matched.
If I execute the Query2 (used in outer search) separately, gives me 20k events matched.
Any help is really appreciated.
Thanks, Arul
... View more