Is it possible to use different timeframes with different indices? For example:
(index=index_a earliest="30/01/18:00:00:00" latest="30/01/18:00:05:00") OR (index=index_b earliest="30/01/18:10:00:00" latest="30/01/18:10:05:00")) dest_ip="10.0.0.1"
What is the right way to do this?
@dkotowsk, I would say using append, but there is sub-search limitation applicable.
index=index_a earliest="30/01/18:00:00:00" latest="30/01/18:00:05:00" dest_ip="10.0.0.1"
| append [search index=index_b earliest="30/01/18:10:00:00" latest="30/01/18:10:05:00" dest_ip="10.0.0.1"]
Once you have data from two base searches what is it that you need to perform?
See if you can use multisearch instead of append.
@dkotowsk, I would say using append, but there is sub-search limitation applicable.
index=index_a earliest="30/01/18:00:00:00" latest="30/01/18:00:05:00" dest_ip="10.0.0.1"
| append [search index=index_b earliest="30/01/18:10:00:00" latest="30/01/18:10:05:00" dest_ip="10.0.0.1"]
Once you have data from two base searches what is it that you need to perform?
See if you can use multisearch instead of append.