I'm querying a datamodel X and I need to append results with same fields names from datamodel xx using. I'm trying with tstats command but it's not working in ES app.
example search:
| tstats append=t `summariesonly` count from datamodel=X where earliest=-7d by dest severity
| tstats summariesonly=t append=t count from datamodel=XX where by dest severity
This will only show results of 1st tstats command and 2nd tstats results are not appended.
Is there any thing wrong here? is there any other way to achieve this?
We have out-of-the-box ES correlation searches that use this pattern and the 2nd tstats with append=t is returning zero result.
Tstats syntax is a little tricky. I suspect you don't have everything you need there on variable names. Try doing a pivot and then looking in search detail (at normalized search I think )
I think maybe you want to do something more like the following with subsearches...
| tstats `summariesonly` count AS Count1 from datamodel=X by dest severity
| append [ | tstats summariesonly=t count AS Count2 from datamodel=XX by dest severity ]
OR maybe to join same dest severity row...
| tstats `summariesonly` count AS Count1 from datamodel=X by dest severity
| join type=left dest severity [ | tstats summariesonly=t count AS Count2 from datamodel=XX by dest severity ]