Splunk Enterprise Security

Multiple tstats with prestats append=t not working in ES app

vj8210
Explorer

Hi,

I'm querying a datamodel X and I need to append results with same fields names from datamodel xx using. I'm trying with tstats command but it's not working in ES app.

example search:

| tstats append=t `summariesonly` count from datamodel=X where   earliest=-7d  by dest severity
| tstats summariesonly=t  append=t count from datamodel=XX where by dest severity

This will only show results of 1st tstats command and 2nd tstats results are not appended.

Is there any thing wrong here? is there any other way to achieve this?

teresachila
Path Finder

We have out-of-the-box ES correlation searches that use this pattern and the 2nd tstats with append=t is returning zero result.

0 Karma

snoobzilla
Builder

Tstats syntax is a little tricky. I suspect you don't have everything you need there on variable names. Try doing a pivot and then looking in search detail (at normalized search I think )

I think maybe you want to do something more like the following with subsearches...

| tstats `summariesonly` count AS Count1  from datamodel=X by dest severity
| append [ | tstats summariesonly=t count AS Count2 from datamodel=XX by dest severity ]

OR maybe to join same dest severity row...

| tstats `summariesonly` count AS Count1  from datamodel=X by dest severity
| join type=left dest severity [ | tstats summariesonly=t count AS Count2 from datamodel=XX by dest severity ]
0 Karma
Get Updates on the Splunk Community!

The Splunk Success Framework: Your Guide to Successful Splunk Implementations

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...