Posted on 20th April 2024
We can join two searches with no command fields by creating a field alias so both the externalid and _id can map per a distinct field. Later you can utilise that field during the searches.
If you want to learn more about this you can go through this blog Splunk Search Commands.
STILL GOT QUERIES?