I have two log statements I'm trying to compare. One statement I'm parsing to return a list of ids, the other I'm parsing to return a single id.
I would like to return a result set whenever a single id also matches an id in a list of ids. I'm trying to use a subquery to do this and I think I have the logic right but it appears that I cannot return a custom field (using the as operator).
_sourceCategory=category1 | parse "Ids [*]" as ids
| where ids matches toString([subquery:_sourceCategory=category2 | parse "Id * " as singleId
| compose singleId])
This results in an error:
Subquery failed with error: Field singleId not found, please check the spelling and try again.
Please sign in to leave a comment.