I have the below 2 searches, which work fine. I need to put the output of both the searches in a single table so the whole data is displayed over ClusterName. Please let me know how I can achieve this.
sourcetype = aaa_sss* eventtype=* | chart values(eventtype) AS Events over clusterName |
clusterName=xxx | timechart span=1m count by eventtype | eval count = ceiling(count/16)