I have two queries
index="gtw-ilb" /v1/platform/change_indicators host="*dev01*"| search sourcetype="nginx:plus:access" |eval env = mvindex(split(host, "-"), 1) | convert num(status) as response_code | eval env = mvindex(split(host, "-"), 1) |eval tenant=split(access_request, "tenantId=")| eval tenant=mvindex(tenant, 1) | eval tenant=split(tenant, "&") | eval tenant=mvindex(tenant, 0) | stats count(eval(like(response_code,"%%%"))) AS total_request count(eval(like(response_code,"4%%"))) AS error_request4 count(eval(like(response_code,"5%%"))) AS error_request5 by tenant | eval pass_percent = round(100-((error_request4+error_request5)/total_request*100),2) | where total_request >1 | table tenant, pass_percent, total_request | sort -pass_percent limit=3
And
index="gtw-ilb" /v1/platform/change_indicators host="*dev01*"| search sourcetype="nginx:plus:access" |eval env = mvindex(split(host, "-"), 1) | convert num(status) as response_code | eval env = mvindex(split(host, "-"), 1) |eval tenant=split(access_request, "tenantId=")| eval tenant=mvindex(tenant, 1) | eval tenant=split(tenant, "&") | eval tenant=mvindex(tenant, 0) | stats count(eval(like(response_code,"%%%"))) AS total_request count(eval(like(response_code,"4%%"))) AS error_request4 count(eval(like(response_code,"5%%"))) AS error_request5 by tenant | eval pass_percent = round(100-((error_request4+error_request5)/total_request*100),2) | where total_request >1 | table tenant, pass_percent, total_request | sort -total_request limit=10
These 2 queries have 90% search criteria common except sorting by column
I want to union of two in one query and extract even duplicate result, what will be that one query please?
... View more