if using mvexpand, my result is like this: Host IP Internet Facing Host A 10.1.1.1 No Host A 172. 1.1.1 Yes for the ip field, i have combined from 2 sources my table should look like this: Host IP Internet Facing Host A 10.1.1.1 Yes 172. 1.1.1 Below is my sample query index=a or sourcetype=b |eval ip=mvappend(IP1, IP2) |stats value(ip) as ip by host | eval "internet facing"=case(cidrmatch(172.1.1.0/24" , IP) , "Yes" , 1=1, "No") I need the result to look like the second example table above, which does not splitting the host.
... View more