I need to return all rows from my top search but add a count of rows from a map or subquery/subsearch.
In my system I have a number of batches which may have a number of errors that exist in a different index and I want to display a count of those errors (even if zero) alongside the batch.
Something like this pseudo query:
search index=A | fields batch_id, batch_name | count = COUNT("search index=B batch_id=$batch_id$ level=error")
This is to display on a dashboard in a stats table:
Id Name Errors
1234 | BatchA | 0
4567 | BatchB | 6
... View more