Posted on 26th July 2024| views
We can join two searches with no command fields by creating a field alias so both the externalid and _id can map per a distinct field. Later you can utilise that field during the searches.
If you want to learn more about this you can go through this blog Splunk Search Commands.