Hello,
I have several different source types and I need to create a report on them, most of them have events with all the fields I need, but one of them doesn't because the events are broken into other events that can become a transaction.
When I pipe only those events to the transaction
command I get all the fields I need, but I don't know how to incorporate the results with the other searches that don't require a transaction.
for example:
This is the search for my normal report:
index=* sourcetype=a sourcetype=b | table file_name, action, user
And this is the search I have to incorporate into the report:
index=* sourcetype=c | transaction id| table file_name, action, user
What can I do?
Thanks.
Try like this
index=* sourcetype=a OR sourcetype=b | table file_name, action, user | append [search index=* sourcetype=c | transaction id| table file_name, action, user]
Try like this
index=* sourcetype=a OR sourcetype=b | table file_name, action, user | append [search index=* sourcetype=c | transaction id| table file_name, action, user]
Yes, this works.
I also found the multisearch command, any recommendations on which might be better?
Thanks