sourcetypes=ship
fields: PortId,ServiceLoopID,VesselName,ID
sourcetypes=route
fields: PORT,LOOP,VS_NAME,SID
I have two sourcetypes above, I want to find out all events in sourcetypes=ship which cannot find in sourcetypes=route.
The matching fields is PortId=PORT, ServiceLoopID=LOOP, VesselName=VS_NAME, ID=SID, how can I do it?
Try this
sourcetype=ship NOT [search sourcetype=route | table PORT,LOOP,VS_NAME,SID| rename PORT as PortId, Loop as ServiceLoopID, VS_NAME as VesselName, SID as ID ] | table PortId,ServiceLoopID,VesselName,ID