Hi,
we are using a session ID to comparing the Client side server side data with diffrent names (session_c session_S). both the data will be in different indexes. where am trying to eliminate the data where sessionID was populating in both in server and client , i just want to filter out the sessionID was populated either only in client side or server side date.
earliest=1h@h ( index=client sourcetype=clientside ) OR (index=server sourcetype=serverside) |dedup session_c, session_S |where session_c!=session_S |stats values(session_c),values(session_S)
I would try something like this (last eval will filterout all sessionID which were appearing in both indexes)
( index=client sourcetype=clientside ) OR (index=server sourcetype=serverside) earliest=1h@h
| eval sessionID=coalesce(session_c, session_S)
| stats values(session_c) as session_c values(session_S) as session_s dc(index) as indexes by sessionID
| where indexes=1
I would try something like this (last eval will filterout all sessionID which were appearing in both indexes)
( index=client sourcetype=clientside ) OR (index=server sourcetype=serverside) earliest=1h@h
| eval sessionID=coalesce(session_c, session_S)
| stats values(session_c) as session_c values(session_S) as session_s dc(index) as indexes by sessionID
| where indexes=1
awesome thank you Somesoni2.