Splunk Search

map command usage for a adding a new column

joydeep741
Path Finder

I have a
SEARCH-1
Which Gives results like

-time column1 column2

I want to run a secondary search for each value of _time and add a column3 added to the existing columns in the result above.

-time column1 column2 column3

I am trying something like this. My old columns get lost in the process. And the number of results are also less.

index=abc sourcetype=sitescopev2log | timechart avg(Availability) by columns | map search="search index=xyz sourcetype=xyz_st | stats count as column3"

Tags (2)
0 Karma

woodcock
Esteemed Legend

Like this:

index=abc sourcetype=sitescopev2log | timechart avg(Availability) BY columns
| append [index=xyz sourcetype=xyz_st | timechart count AS column3]
| timechart avg(*) AS *
0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...