Hi folks, newbee here, I'm trying to do this:
| stats values(duration) as DaysSinceLastAccess, count(duration) as Actual by duration
| join DaysSinceLastAccess [| inputlookup static_lookup.csv]
The problem is that the join only join on the values up to the max value i have from my real data. e.g. DaysSinceLastAccess is 22 days, but in the lookup, DaysSinceLastAccess goes up to 180
I wish to return all rows from lookup, I guess I could append the missing days to values(duration)?
Thanks
Try this
... | stats count as Actual by duration | rename duration AS DaysSinceLastAccess | append [| inputlookup static_lookup.csv ] | stats max(count) as Actual by DaysSinceLastAccess