Splunk Search

How do I append new columns for different search results?

govindparashar1
New Member

I wants to append multiple search results in separate columns.
The following searches are fetched from different source types.

Search 1.

.......uri_path="/landing/view/*" method=POST |  stats dc(sessionId) as A by date_month

Search 2.

......."REBOOKED_ACTIONED" | stats dc(session_id) as B by date_month

Search 3.

.......uri_path="/cancel/confirmed/*" method=POST |  stats dc(sessionId) as C by date_month

Expected Result in the following format:

Date_Month   A    B    C   pec_B             pec_C  
JAN-2016     20   10   2   (10*100)/A=50%   10%
DEC-2015     40   30   5   75%             12.5%

Please advise..

0 Karma

somesoni2
Revered Legend

Try something like this

(base search 1 i.e. sourcetype=soucetypeA uri_path="/landing/view/*" method=POST) OR (base search2 i.e. sourcetype=soucetypeB "REBOOKED_ACTIONED") OR (base search 3 i.e. sourcetype=soucetypeC uri_path="/cancel/confirmed/*" method=POST ) | stats dc(sessionId) over date_month by sourcetype | rename sourcetypeA as A sourcetypeB as B sourcetypeC as C  | eval pec_B=(B*100)/A  | eval pec_C=(C*100)/A
0 Karma

vasanthmss
Motivator

Hi,

Try this,

.......uri_path="/landing/view/*" method=POST |  stats dc(sessionId) as A by date_month | sort 0 date_month | appendcols [......."REBOOKED_ACTIONED" | stats dc(session_id) as B by date_month | sort 0 date_month  ] | appendcols [ .......uri_path="/cancel/confirmed/*" method=POST |  stats dc(sessionId) as C by date_month | sort 0 date_month ]

Thanks,
V

V
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...