I have two queries like as below :
> index="int_audit_dev" | chart count(ApplicationName) over ApplicationName by Status
> index="int_audit_dev" | chart count(event.ApplicationName) over event.ApplicationName by event.Status
Individually these two queries are fine and able to get the data in tabular format. But I want the data as a sum of values in tabular format.
Any suggestions?
I want to add the results of below two queries
> index="int_audit_dev" | chart count(ApplicationName) over ApplicationName by Status |addtotals
> index="int_audit_dev" | chart count(event.ApplicationName) over event.ApplicationName by event.Status |addtotals
index="int_audit_dev" |eval status=coalesce(Status,event.Status), applicationName=coalesce(ApplicationName,event.ApplicationName)| chart count(applicationName) over applicationName by status
Can you provide an example of what you currently have and what you would like
I want to add the results of below two queries
index="int_audit_dev" | chart count(ApplicationName) over ApplicationName by Status |addtotals index="int_audit_dev" | chart count(event.ApplicationName) over event.ApplicationName by event.Status |addtotals
Example :
query 1 : index="int_audit_dev" | chart count(ApplicationName) over ApplicationName by Status |addtotals
for the above query, I am getting as below
a 5
b 8
query 2 : index="int_audit_dev" | chart count(event.ApplicationName) over event.ApplicationName by event.Status |addtotals
for this query, the results will be like
a 3
b 6
Now I need a single query to add above both values and display in Dashboard like below (adding above both table data):
a 8
b 14