I have a search that works with stats - but fail to work when using tstats..
Here is the search with stats:
index=wineventlog sourcetype="xmlwineventlog:security" earliest=-15m@m-1w latest=@m-1w | stats count by host | rename count as LastWeek
| appendcols [search index=wineventlog sourcetype="xmlwineventlog:security" earliest=-15m@m latest=@m | stats count by host | rename count as Today]
| table host Today LastWeek
Since this search take some time - I thought that I should use tstats instead - but some how I can't make it work. The individual
searches works - but not combined as subsearch as in this example:
| tstats count where index=wineventlog sourcetype="xmlwineventlog:security" earliest=-15m@m-1w latest=@m-1w by host | rename count as LastWeek
| appendcols [search [|tstats count where index=wineventlog sourcetype="xmlwineventlog:security" earliest=-15m@m latest=@m by host | rename count as Today]]
| table host LastWeek Today
In this search it only returns values for "LastWeek" - nothing for "Today", but the individual searches with tstast works without problems.
Anyone with a clue?
The
[search [|tstats
is seeing
|tstats
as a subsearch of an empty subsearch. Remove the
[search...]
and it should work:
| tstats count where index=wineventlog sourcetype="xmlwineventlog:security" earliest=-15m@m-1w latest=@m-1w by host | rename count as LastWeek
| appendcols [|tstats count where index=wineventlog sourcetype="xmlwineventlog:security" earliest=-15m@m latest=@m by host | rename count as Today]
| table host LastWeek Today
Ok, thank you!
I knew it was something simple - sometimes you need someone else eyes - to see the obvious...
Thanka, again.
The
[search [|tstats
is seeing
|tstats
as a subsearch of an empty subsearch. Remove the
[search...]
and it should work:
| tstats count where index=wineventlog sourcetype="xmlwineventlog:security" earliest=-15m@m-1w latest=@m-1w by host | rename count as LastWeek
| appendcols [|tstats count where index=wineventlog sourcetype="xmlwineventlog:security" earliest=-15m@m latest=@m by host | rename count as Today]
| table host LastWeek Today