Hello,
I want total of multiple searches in timechart per week.
My search in simple format last 90 days:
| inputlookup abcd.csv | search host=*CC* | dedup host | stats count(host) as "List1"
| appendcols
[| inputlookup efgh.csv | search host=*AA* | dedup host | stats count(host) as "List2"]
| appendcols
[| inputlookup xyz1.csv | search host=*BB* | dedup host | stats count(host) as "List3"]
| eval Total=List1+List2+List3
| timechart span=w@1w sum(Total) as "Hosts"
If I run it without last timechart line, then it gives me total for 90 days or 1 week, but I need same results calculated weekly using timechart, and display total per week.
Hi @utk123,
Assuming you have _time field in all your lookup files you can try something like below;
| inputlookup abcd.csv where host="*CC*" | eval list="List1"
| inputlookup append=t efgh.csv where host="*AA*" | eval list=coalesce(list,"List2")
| inputlookup append=t xyz1.csv where host="*BB*" | eval list=coalesce(list,"List3")
| bin _time span=w@1w
| stats dc(host) as host_count by list _time
| timechart span=w@1w sum(host_count) as Total
I get below error:
Error in 'inputlookup' command: This command must be the first command of a search.
Do you have anything before the search you sent us? If yes, we should find another way to do it.