what i would do is to format the log before forwarding to splunk. even you can successfully submit it , you will face trouble when querying.
... View more
follow the logic shown in this query:
search 1st | stats count as count1 | join [search 2nd|stats count as count2] | fields count1 count2 | transpose
let me know if it works for you.
... View more