I have 2 search queries one is main and the other one is a subquery and i need to find the count difference between both the searches
The subquery is not returning value not sure why.
Query 1 : eventtype=* | search status=200 | stats count as successCount
Query2 : eventtype=* | search status=500 | stats count as failedCount
I need to find both the count and calculate difference between them and display it
Do you mean something like this?
base search
| stats count
| eval diff = count - [ subsearch | stats count | return $count ]