Hi,
I have 2 indexes.
measurements - list of all measurements ( _time, transactionId, transTime, resultStatus)
incidents - list of incidents ( _time, transactionId, incidentId, startTime, endTime, valid, checked, comment)
_time in the incidents table is the time that the incident is inserted into Splunk.
i would like to check for each measurement if it was between the startTime and endTime of a valid incident on that transaction and add a field "availability" with 0 if it was in an incident and 1 if it was not to each measurement.
i tried things with map command and join but i cant find the right approach. please help:)
thanks!
... View more