Splunk Enterprise

Results are miss match while using appedcols

marisstella
Explorer

Hello everyone,

I am getting incorrect values while using appendcols to fetch the different results like a currentweek, 1weekago,  2weeksago.

 

|bin _time span=1h |
stats count{trid) as transaction_count_1WAgo avg(duration) as Average RT_1WAgo by _time ABC | fields *
 
|appendcols [search earliest=** latest=** |
|bin _time span=1h
| stats count(trid) as transaction_count_2WAgo avg(duration) as Average RT_2WAgo by _time ABC | fields *
]
 
|appendcols [search earliest=** latest=** |
|bin _time span=1h |
stats count{trid) as transaction_count_currentweek avg(duration) as Average RT_currentweek by _time ABC| fields *]
 
If I run all this queries individually it shows some results and when I am trying to use them in a single search by appending using "appendcols" they shows different..
 
Please suggest on this?
Note: i have used all latest, earliest time frames correctly but didn't show here.
Labels (3)
0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...