I have some conditions for each search as follows:
Search A
index=users Channel=40
| eval Token = User."-".Channel
| stats count by Token
Search B
index=mobile Code=5 OR Code=3 AND Mobile=1 OR Mobile=2
| stats count by Connection
Search C
index=mobile Code=5 OR Code=3 AND Mobile=5 OR Mobile=3 channel=*
| eval Token = user."-".channel
| stats count by Token
Should I save those counts separated? How can I do that...
My main table should show:
Search A count
Search B count
Search C count
Search A + Search B count
Search A + Search C count
Search B + Search C count
Search A + Search B + Search C count
It's like 3 queries inside one main query, but counts are different...
Note that in Search A Channel has an Upper case and in Search C it's lower case...
another approach is to run 3 searches and to save the results with a summary indexing or an outputlookup command.
then run a 4rd search retrieving the results from each of them (summary search, or inputlookup with appendcols/append)
Do not forget to add an extra column to your results for the value A/B/C to distinguish them