I have two different indexes that have different fields name which are actually the same thing:
For example:
Index 1 has: IPV4_SRC_ADDR : "75.72.214.200"
Index 2 has: source.addr: "75.72.214.200"
I cannot modify the index but I can work on the index pattern. Is there a way that I can create an additional field to filter on to click and get the only results from that ip?
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.