Splunk Enterprise Security

Multiple tstats with prestats append=t not working in ES app

vj8210
Explorer

Hi,

I'm querying a datamodel X and I need to append results with same fields names from datamodel xx using. I'm trying with tstats command but it's not working in ES app.

example search:

| tstats append=t `summariesonly` count from datamodel=X where   earliest=-7d  by dest severity
| tstats summariesonly=t  append=t count from datamodel=XX where by dest severity

This will only show results of 1st tstats command and 2nd tstats results are not appended.

Is there any thing wrong here? is there any other way to achieve this?

teresachila
Path Finder

We have out-of-the-box ES correlation searches that use this pattern and the 2nd tstats with append=t is returning zero result.

0 Karma

snoobzilla
Builder

Tstats syntax is a little tricky. I suspect you don't have everything you need there on variable names. Try doing a pivot and then looking in search detail (at normalized search I think )

I think maybe you want to do something more like the following with subsearches...

| tstats `summariesonly` count AS Count1  from datamodel=X by dest severity
| append [ | tstats summariesonly=t count AS Count2 from datamodel=XX by dest severity ]

OR maybe to join same dest severity row...

| tstats `summariesonly` count AS Count1  from datamodel=X by dest severity
| join type=left dest severity [ | tstats summariesonly=t count AS Count2 from datamodel=XX by dest severity ]
0 Karma
Get Updates on the Splunk Community!

Splunk Lantern | Spotlight on Security: Adoption Motions, War Stories, and More

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Splunk Cloud | Empowering Splunk Administrators with Admin Config Service (ACS)

Greetings, Splunk Cloud Admins and Splunk enthusiasts! The Admin Configuration Service (ACS) team is excited ...

Tech Talk | One Log to Rule Them All

One log to rule them all: how you can centralize your troubleshooting with Splunk logs We know how important ...