How do calculate the difference between the count of the following searches.
Tried to use the eval, but does not return results.
Need to find RunningJobs=Query1 - (Query2+Query3)
or
RunningJobs=Action1 - (Action2 - count(jobid))
index=aap_prod sourcetype="HDP:PROD:OOZIE" ":start:] with user-retry state" | rex "TOKEN\[\] APP\[(?<JobName>[^\]]*)" | rex "ACTION\[[^\@]*(?<Action1>[^\d\]]*)" | search Action1="@:start:"| stats count(Action1)
| append [search index=aap_prod sourcetype="HDP:PROD:OOZIE" "@end***]Action updated in DB!" | rex "TOKEN\[\] APP\[(?<JobName>[^\]]*)" | rex "ACTION\[[^\@]*(?<Action2>[^\d\]]*)"| search Action2="@end"| stats count(Action2)]
| append [search index=aap_prod sourcetype="HDP:PROD:OOZIE" "ENDED WorkflowKillXCommand" | rex "TOKEN\[\] APP\[(?<JobName>[^\]]*)" | rex "ACTION\[[^\@]*(?<Action>[^\d\]]*)" | rex "JOB\[?(?<jobid>[\d-]+)-" | stats count(jobid)]
How about this?
index=aap_prod sourcetype="HDP:PROD:OOZIE" ":start:] with user-retry state" | rex "TOKEN\[\] APP\[(?<JobName>[^\]]*)" | rex "ACTION\[[^\@]*(?<Action1>[^\d\]]*)" | search Action1="@:start:"| stats count(Action1) as Query1
| append [search index=aap_prod sourcetype="HDP:PROD:OOZIE" "@end***]Action updated in DB!" | rex "TOKEN\[\] APP\[(?<JobName>[^\]]*)" | rex "ACTION\[[^\@]*(?<Action2>[^\d\]]*)"| search Action2="@end"| stats count(Action2) as Query2]
| append [search index=aap_prod sourcetype="HDP:PROD:OOZIE" "ENDED WorkflowKillXCommand" | rex "TOKEN\[\] APP\[(?<JobName>[^\]]*)" | rex "ACTION\[[^\@]*(?<Action>[^\d\]]*)" | rex "JOB\[?(?<jobid>[\d-]+)-" | stats count(jobid) as Query3] | eval RunningJobs = Query1 - (Query2 + Query3)
I believe you want to use appendcols here instead of append, in order for last eval to work.
@somesoni2 that works
hi athorat,
that is a example:
index=summary source="dailysearch" earliest=-7d@d latest=@d
| stats count as TotalA
| appendcols
[search index=summary source="hourlysearch" earliest=@d latest=now
| stats count as TotalB]
| eval Total=TotalA+TotalB
| fields Total
for more infomations, try following this link:
https://answers.splunk.com/answers/13927/adding-the-result-of-2-stats-count-queries.html