The counts were calculated via index=index_1 (sourcetype=source_1 field_D="Text" field_E=*Down* OR field_E=*Up*) OR (sourcetype=source_2)
| dedup field_B keepempty=true
| eval field_AB=coalesce(field_A, field_B)
| where isnotnull(field_AB)
| stats dc(field_AB) as count by sourcetype To your point about source vs. sourcetype, I realized that after looking at those counts and made both of my filters use sourcetype. As for my Initial Query Results, let me clarify that for you: UniqueID is not the same value in every row. It can occur more than once, yes, as this log is reporting the status of the device as it goes up and down. As for field_C, to clarify from my initial post: field_C is an identifier which can be mapped to multiple field_AB. field_C is the only field from source_2 I really want to add to source_1. Essentially I'm using source_2 as a reference to pull field_C from, matching all instances of UniqueID_X to whichever corresponding field_C. Here is what it looks like with that in mind: Inital Query Results field_D field_AB field_C field_E DeviceType UniqueID_1 Up DeviceType UniqueID_2 Down UniqueID_3 Data_2 UniqueID_4 Data_1 As well as expected results: field_D field_AB field_C field_E DeviceType UniqueID_1 Data_1 Up DeviceType UniqueID_2 Data_2 Down DeviceType UniqueID_3 Data_2 Down DeviceType UniqueID_4 Data_1 Down Additionally, here is raw data from source_1: 2024/03/07 09:06:12.75 ET,ND="\A001 ",DIP="$ABC0.",Sys=B002,Serv=C,Ent="AAA-BBBBBB ",AppID=0000,LogID=1111,field_A="AA000111 ",Alias=" ",Tkn1="222222222 ",Tkn2="333333333 ",field_D="DeviceType",field_E="BB AA000111 (00) Down, error 0000" And here is raw data from source_2 (field_B and field_C are towards the bottom): BSYS= ,EXL= ,HI= ,HSTT= ,MBR= ,NAME= ,ORRR= ,RDDD= ,REV= ,LINK=0000,POSTDATE=240307,RESP= ,RESP_ERR= ,R= ,D= ,DE= ,RECOM= ,SCORE= ,STAND= ,ROUTE=00000000,NUM=0000000000,NUM1=0000000000,NUM2=0000000000,NUM3=000000000,CODE=1,POS=P,RNDTTT= ,AUTH=000000,ASYS=0-,AN=A000 ,RCODE= ,TIMEIN=24030709061224,BURNRES= ,BURNRT=00000,BURNS=00000,ACCEPTCODE=0000,ACCEPTNAME=00000000000000 ,ANOTHERID=AAA ,INPUT_CAP=0,INPUTMODE=0,ST=00,STATE=AA,LEVEL= ,COMREQ=0,PDATE=240308,CCODE=000,RTD= ,CCC= ,CCC_RES= ,CCC_RES2= ,SCODE= ,DACTUIB= ,DDD= ,DDDR= ,DDDE= ,DDDEB= ,DDDN= ,DDDT= ,DDDF= ,DDDM= ,DDDM2= ,DDMN= ,DDOI= ,DDRN= ,DDRC= ,DDAF= ,DDTA= ,DDTAF= ,DDTT= ,EI= ,EARD= ,EERD= ,EEFT= ,ESSS= ,EAS= ,EFRT= ,EH=AAA0AAA ,EII=AAAAAAA0,EO=AAAAA00B,FMS= ,FPPP= ,FAT=00,GRC=00,HS=00,HII=00000000,ITN=AAA03,ISS=0000,JT=240307090612,LAA=0000000000,LAA2=0000000000,MSI= ,MIDD=AAAAA AAAAAAAAAAA,MT=0000,MMMM= ,MMOD= ,MMOS= ,MMU= ,MD= ,MDDD= ,MRRC= ,MRRRR= ,MSGGG=0,MSGGG=0000,MCS= ,MCQ= ,NCF= ,NPD=240308,NII=AAA,NPPC= ,NNNPPP= ,NNNPPPR= ,NTNT= ,NTNTR= ,OSS=00,OOM= ,PADD= ,POOOS=000,PDCCC=000000000A,PSC12=000000 ,PSCSC=11111111,PTTTID= ,QTIME=11111,RAII=111111111,REIII=77775750 ,RTDDD= ,RTRRR= ,RTRRRS= ,RIII=BBBBBBB ,RSSST=AA ,RSAAAA=AAAA B CCCCCCCCC DD EE,RRRC=00,RTTTTT=00000,RESSSCC=A,RSSS=0,RSCC=A,EFFN=00000000,RCCCC=00,RMRRM= ,RRTD= ,PREPRE=000000 ,SSTS=00,SNNN=000000,Ssrc=,STMF=00000000,field_B=AA000111,SCCA=00000000,SCCA=00000000,STQQ=000000,SYSTEMTRACE=00000000000,TIST=00000,field_C=AA00 ,TOID=00000000,TST=OK,TT=00,TIMEZONE=*,ACCT=00,TDA= ,TDARID= ,TCC=00,TNID=000000,TTTDM=240307080559,TTTIII=0000000000000000,VRES= Hope that clears it up.
... View more