Hi,
Can someone help me?
I have the searches below and need to be combine the two to display the expected results:
LastWKTotal ThisWKTotal Difference
ABC
DEF
GHI
.
Searches:
index=xxx host=xxx sourcetype=ABC* Agent_NumberOfAgents=* earliest=-14d@d latest=-7d@d | dedup host | stats sum(Agent_NumberOfAgents) as LastWKTotal | appendcols [search index=XXX host=xxx sourcetype=ABC* Agent_NumberOfAgents=* earliest=-7d@d latest=now | dedup host | stats sum(Agent_NumberOfAgents) as ThisWKTotal] | eval Platform="ABC" | eval Difference=ThisWKTotal-LastWKTotal
and
index=XXX host=XXX sourcetype=ABC* Agent_NumberOfAgents=* earliest=-14d@d latest=-7d@d | dedup host | stats sum(Agent_NumberOfAgents) as LastWKTotal | appendcols [search index=XXX host=XXX sourcetype=ABC* Agent_NumberOfAgents=* earliest=-7d@d latest=now | dedup host | stats sum(Agent_NumberOfAgents) as ThisWKTotal ] | eval Platform="DEF" | eval Difference=ThisWKTotal-LastWKTotal
Thanks in Advance
Give this a try
index=xxx host=xxx (sourcetype=ABC* OR sourcetype=DEF*) Agent_NumberOfAgents=* earliest=-14d@d latest=now
| eval Platform=if(like(sourcetype,"ABC%"),"ABC","DEF")
| eval week=if(_time>=relative_time(now(),"-7d@d"),"ThisWKTotal","LastWKTotal")
| dedup week Platform host
| chart sum(Agent_NumberOfAgents) over Platform by week | eval Difference=ThisWKTotal-LastWKTotal
If I understand what you mean, you just want to daisy-chain results from different searches... you should be able to do that simply with:
<INSERT_FIRST_SEARCH_HERE> | append [ search <INSERT_SECOND_SEARCH_HERE> ] | append [ search <INSERT_THIRD_SEARCH_HERE> ]
Etc.
should sourcetypes be DEF* in the 2nd search? ...
should both searches provided by combined together, or are they examples of you trying to combine 2 searches together?
I ask because they are the same exact search only in the 2nd one you eval Platform="DEF" at the very end.
Also, would be great if you provided example data.