@livehybrid tried your solution its not working i was able to resolve this using | makeresults | eval APP1="appdelta", hostname1= mvappend("syzhost.domain1","abchost.domain1","egfhost.domain1"),hostname2=mvappend("syzhost.domain1","abchost.domain1") | fields - _time | eval match=max(mvmap(hostname1, if(isnotnull(mvfind(hostname2, hostname1)), 1, hostname1))) | table APP1,hostname1,hostname2,match but now i have a additional issue for some hostnames is "no hosts" in that case also its just giving me 1 hostname | makeresults | eval APP1="appdelta", hostname1= mvappend("syzhost.domain1","abchost.domain1","egfhost.domain1"),hostname2=("") | fields - _time | eval match=max(mvmap(hostname1, if(isnotnull(mvfind(hostname2, hostname1)), 1, hostname1))) | table APP1,hostname1,hostname2,match which is not right
... View more