Hi,
I have this search which gives me error % and good requests, etc. When I get this alert, I would also like to send an another table in the same alert results where I can show the top 5 URIs by the error status. Would it be possible?
(status=200 OR status>399) | eval requestType = if(status==200, "OK", "Error") | chart count as requests over host by requestType | rename "requests: OK" as OK ,"requests: Error" as Error | eval TotalRequests= (OK+Error) | eval GoodRequestsPerc = round((OK/TotalRequests)*100,2) | eval FailuresPerc = round((Error/TotalRequests)*100,2) | table host, OK,Error,GoodRequestsPerc, FailuresPerc | sort -"FailuresPerc" | where FailuresPerc > 5
you can use this command :
| set union [ search 1] [ search 2]