Hello,
I have a behavior that I don't understand yet.
The search string below give me the expected results :
search sourcetype=sourcetype_1
| where ...
| stats count ...
| fields Date,sourcetype,host,msg
And the same execute as a subsearch doesn't show anything :
([search sourcetype=sourcetype_1
| where ...
| stats count ...
| fields Date,sourcetype,host,msg])
My goal is to queue different search and gathering in the same search string such as below :
([search sourcetype=sourcetype_1
| where ...
| stats count ...
| fields Date,sourcetype,host,msg])
OR
([search sourcetype=sourcetype_2
| where ...
| stats count ...
| fields Date,sourcetype,host,msg])
OR
([search sourcetype=sourcetype_3
| where ...
| stats count ...
| fields Date,sourcetype,host,msg])
Thanks for your help,
I am not sure if I fully understand your requirement here. Subsearches are basically parameters to main search to filter data from it. You can't use them to add result to main search. Based on your example, I am guessing you want to consolidate data from different searches (returning same fields) into one big search. For that you can try append command as following:
sourcetype=sourcetype_1
| where ...
| stats count ...
| fields Date,sourcetype,host,msg
| append [search sourcetype=sourcetype_2
| where ...
| stats count ...
| fields Date,sourcetype,host,msg]
| append [search sourcetype=sourcetype_3
| where ...
| stats count ...
| fields Date,sourcetype,host,msg]
OR if the where and stats conditions are same in all three search (including field names), you can do like this
sourcetype=sourcetype_1 OR sourcetype=sourcetype_2 OR sourcetype=sourcetype_3
| where ...
| stats count ...
| fields Date,sourcetype,host,msg
Are where condition and stats command same for all three queries?
The append command works for my case !
But this seems not compatible with real time...
Thanks,