Join or Subquery Help

Comments

1 comment

  • Avatar
    Andrew McLean

    This should work: 

    _sourceHost=host 1
    | json field=_raw "data.type" as type
    | where type ="gd_auth_succeed"
    | where [subquery: _sourceHost=prod_auth0
    | json field=_raw "data.type" as type
    | where type ="gd_auth_failed"
    | compose user_id]
    | count user_id

    0
    Comment actions Permalink

Please sign in to leave a comment.