e.g QUERY 1: host=jtcstcxbsswb* source="/usr/IBM/HTTPServer/logs/access*" httpmethod="GET" statuscode="200" loaninfo="/api*" OR Requestinfo="*/" OR sitename="*/LoginAccountUserName" |eval APFields=split(loaninfo,"/") |eval APNumOfFields=mvcount(APFields) |eval AP2ndFromLast=mvindex(APFields,APNumOfFields-2) |eval APLoanNumber=mvindex(APFields,6) |eval APLast=mvindex(APFields,-1) |search APLast="loans" OR APLast="summary" OR APLast="payments" |timechart count(APLast), Avg(cookie) as URT by APLast Query 2 :sourcetype=apigee:digit* host=JTCLSGLAPGERT* APIProduct=*-Authenticated-Product |timechart span=5m distinct_count(LoginAccountUserName) i want something like this host=jtcstcxbsswb* source="/usr/IBM/HTTPServer/logs/access*" httpmethod="GET" statuscode="200" loaninfo="/api*" |eval APFields=split(loaninfo,"/") |eval APNumOfFields=mvcount(APFields) |eval AP2ndFromLast=mvindex(APFields,APNumOfFields-2) |eval APLoanNumber=mvindex(APFields,6) |eval APLast=mvindex(APFields,-1) |search APLast="loans" OR APLast="summary" OR APLast="payments" |stats count(APLast), Avg(cookie) as URT by APLast |append [search sourcetype=apigee:digit* host=JTCLSGLAPGERT* APIProduct=*-Authenticated-Product |timechart span=5m distinct_count(LoginAccountUserName) ] |bin _time|stats count(APLast), Avg(cookie) as URT ,distinct_count(LoginAccountUserName) by APLast I am able to get the data as Time | count(APLAST) | URT | LoginAccountUserName (I see only zero values in LoginAccountUserName) how to fetch the LoginAccountUserName data from 2nd query and list it here.
... View more