I want to search all the email logs for a mail transaction. However we have multiple indexes for our mail logs.
When i run the search below , it gets the qid which is the expected behavior.
sourcetype=INDEX_B index=INDEX_B
[search sourcetype=INDEX_A to=*<email address>* | fields msgid |rename msgid as hdr_mid] | table qid
where:
msgid/hdr_mid = unique email id in index_A. I have to rename msgid to hdr_mid as thats the name of the field in INDEX_A
qid = another unique id in INDEX_B that corresponds to INDEX_A
What i want to accomplish is that the result of the qid will immediately search all match in INDEX_B but its not generating any search result. Below is the modified version i made.
sourcetype=INDEX_B index=INDEX_B
[search sourcetype=INDEX_B index=INDEX_B | search
[search sourcetype=INDEX_A to=*<email address>* | fields msgid |rename msgid as hdr_mid | rename qid as search]] | table qid
... View more