index=firstindex OR index=secondindex
[|inputlookup mylookup.csv field1]
|stats dc(index) as flag by field1
|where flag>1
|table field1
Hi, @sherins
this is assuming field1 is the common field among indexes.
how about this?
...everybody wants to join the searches...
index=secondindex
| join field1
[ search index=firstindex
|lookup mylookup.csv field1 as field1
| table field1] ]
Assuming field1
is the common field among indexes and lookup file, try below query.
index=index-1
| join field1
[ search index=index-2
| table field1
| search
[| inputlookup mylookup.csv
| table field1] ]