index="index1" sourcetype=sourcetype1 | join commonfield [ search <br>index="index2" sourcetype=sourcetype2 ] | sort _time | stats <br>last(index1field1) as state by index2field1, index1field2, index1field3 <br>| where index1field1 != "UP" | dedup index2field1 | stats count
我想在不使用统计信息或OR的情况下优化此查询,而没有人可以帮助我吗?
答案 0 :(得分:0)
(index="index1" sourcetype=sourcetype1) OR (index="index2" sourcetype=sourcetype2)
| stats values(*) AS *, values(_*) as * by commonfield
这将是一个很好的起点。首先引入两组数据,然后合并来自两个源的所有字段,并根据commonfield