Failing to do a join on 2 simple queries

Comments

2 comments

  • Avatar
    Graham Watts

    Hi Munya,

    Here is one option to show userId's that have a success and failure, is this what you're looking for?

    If not, what use case are you trying to solve?

    _sourceHost=<redacted> (gd_auth_failed OR gd_auth_succeed)
    | parse "user_id:*" as userId, "type:*" as type
    | if(type="gd_auth_succeed",1,0) as gd_auth_failed
    | if(type="gd_auth_failed",1,0) as gd_auth_failed
    | sum(gd_auth_succeed) as succeed_total, sum(gd_auth_failed) as failed_total by userId
    | where succeed_total > 0 and failed_total > 0


    0
    Comment actions Permalink
  • Avatar
    munya.mufambisi

    thanks Graham! that actually solves my use case!

    0
    Comment actions Permalink

Please sign in to leave a comment.