Hi All, I have 2 different queries and I want to combine their results. These 2 queries return a single value output I want these 2 values in the same search result. Thanks for any help.
...
See more...
Hi All, I have 2 different queries and I want to combine their results. These 2 queries return a single value output I want these 2 values in the same search result. Thanks for any help.
index=“abc” (TYPE="Run bot finished" OR TYPE="Run bot Deployed") | search STATUS=Successful TYPE="Run bot finished" | stats count |rename count as Success_Count
index = “abc” RPAEnvironment = "prd" ProcessName = "*" LogType = "*" TaskName = "*Main*" (LogLevel=ERROR OR LogLevel=FATAL)
| eval Time = strftime(_time, "%Y-%m-%d %H:%M:%S")
| eval LogDescription = trim(replace(LogDescription, "'", ""))
| eval LogMessage = trim(replace(LogMessage, "'", ""))
| eval TaskName = trim(replace(TaskName, "'", ""))
| eval host=substr(host,12,4) | eval Account=if(User!= "" ,User,LoginUser)
| table Time, LogNo, host, Account, LogType, LogMessage, TaskName ,ProcessName
| rename LogMessage as "Log Message", TaskName as "Task Name", host as "VDI" | sort - Time|stats count|rename count as Failure_Count