I am trying to join two searches together to table the combined results by host.
First search below is showing number of events in the last hour by host, index, and sourcetype:
| tstats count where index=* by host, index, sourcetype | addtotals | sort -Total | fields - Total | rename count as events_latest_hour
Second search is showing the ingest per hour in GB by host.
(index=_internal host=splunk_shc source=*license_usage.log* type=Usage)
| stats sum(b) as Usage by h | eval Usage=round(Usage/1024/1024/1024,2) | rename h as host, Usage as usage_lastest_hour | addtotals | sort -Total | fields - Total
Can you please help with how i would join these two searches together to display the host, index, sourcetype, events_latest_hour, usage_lastest_hour
Basically i want to table the results of the first search and also include the results "usage_lastest_hour"from the second search into the table.
... View more