I needs to apply left outer join or NOT IN condition on two different search
search 1 :
index=abc host="*xxx*" sourcetype=access_combined_wcookie NOT (sessionId="-" OR isnull(sessionId)) method=GET
uri_path="/x/y/z*" | rex field=uri "^(?:[^/\\n]*/){4}(?P\\d+)" | eval pk=sessionId+CTM | dedup pk | table pk
Search 2:
index=def sourcetype=referral_activity APPOINTMENT_BOOKING_BOOKED | eval pk =substr(session_id, 9)+ctm | table pk |
join type=inner pk [search index=abc host="*xxx*" sourcetype=access_combined_wcookie NOT (sessionId="-" OR isnull(sessionId))
method=POST uri_path="/x/y/w*" | rex field=uri "^(?:[^/\\n]*/){4}(?P\\d+)" | eval pk=sessionId+CTM | dedup pk | table pk ]
Expected results : Unique pk values from search 1 which is not present into search 2 results
Please advise..
↧