Continuing the discussion from Comparing 2 sources of log input ( using fuzzy? hash? term ?):
So, I am trying to get a range of messages using timestamps from 2 different data source and compare them see if they match (say match on particular timestamp & messageid combination)
Should I do comparison on multiple message using the following?
- they are 2 different indices
- create 2 different docs (doc_a and doc_b) under the same index?
And how to do comparison between messages (timeA-timeB) from source 1 and source 2. I look into mlt, it doesn't seem to be for comparing 2 arrays of messages.