I have been searching for this for a bit now and haven't come up with anything just yet. I am trying to take a list of devices in one index and see if the same name exists in another index. An example would be looking up my computer in one index and seeing if it exists in our index that contains anti-virus information. Any help or direction would be great.
Or something like this. (same assumption as @richgalloway, common field exists between two indexes)
index=index2 [search index=index1 | stats count by commonfield | table commonfield]
index=index1 | fields computer | join type=inner computer [search index=index2] | ...
This assumes the field computer
exists in both indices. If it doesn't add a rename
command before the join
.
Please accept the answer.
Works great. Thanks for the fast response.