Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

chain 2 search queries and get the earliest and latest of different fields

$
0
0
search string1 - [ field1 ] search string2 [ field1 field2] search string3 [ field1 field2] I want the results of search string 1 to be matched with search string 2 by the common field (which is field 1) and the results of this to be matched with search string 3 where the common field is field 2, then I want to get those results as output with the earliest of field 1 and latest of field 2. I've tried the subsearch command with join but it doesn't generate the required results. Also tried append. Please help!

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>