I've got a search defined in a simple dashboard:
<query>index=scm sourcetype=jenkins_test_summary test summary| head 1</query>
And I reference that search further down in the panels. In one of them:
<query>stats last(failures) as Failures by tests</query>
That works. But if I modify this to include an appendcols command:
<query>stats last(failures) as Failures by tests | appendcols [search index=test | stats count as TOTAL | fields TOTAL]</query>
The panel fails with the error: "Error in appendcols command: You can only use appendcols after a reporting command (such as stats, chart or timechart)."
REALLY curious... if I click the magnifying glass, bottom left of the panel, to open in search, the entire search works as intended.
Am I missing something, or is this a bug with the postProcess feature? Running on Splunk Enterprise 6.2.4 Linux 64-bit.
Only the base search actually runs the search job. The reference search act as filter and/ or modifiers of the original data. The base search should include all data need in post process search, because they will not initiate a search job.
View solution in original post