Hello! I'm looking to get a time range from two events, one from a standard search, the other from a different search based on a regex derived from a third search and report the difference in times between the events. However I'm struggling to either make the multisearch work with map, or multireport/append work in a panel, even though those searches work just fine in the regular search bar. To give you an idea, I have the failed multisearch (which doesn't work due to me using map):
| multisearch [| search index=index1 "First text string"] [| search index=index1 "text string for regex lookup" | rex field=message "^(?<LookUp>\d+)\s" | map search="search index=index1 message = $LookUp$*"] | stats earliest(_time) as time1, latest(_time) as time2 | eval difference=time2-time1 | eval difference=tostring(difference, "duration") | table time1 time2 difference
Obviously this doesn't work due to non-streaming commands, but multireport does, however it does not work in a standard statistics table panel, or any other panel that I've tried, just giving me a "search is waiting for input" message:
| multireport [| search index=index1 "First text string"] [| search index=index1 "text string for regex lookup" | rex field=message "^(?<LookUp>\d+)\s" | map search="search index=index1 message = $LookUp$*"] | stats earliest(_time) as time1, latest(_time) as time2 | eval difference=time2-time1 | eval difference=tostring(difference, "duration") | table time1 time2 difference
The other option is append which once again works in the regular search but not in the panel search:
index=index1 "First text string" | append [ search index=index1 "text string for regex lookup" | rex field=message "^(?<LookUp>\d+)\s" | map search="search index=index1 message = $LookUp$*"] | stats earliest(_time) as time1, latest(_time) as time2 | eval difference=time2-time1 | eval difference=tostring(difference, "duration") | table time1 time2 difference
I've been trying to find a way to do this but with no luck - if anyone has anything they can spot or advise that would be greatly appreciated.
Thank you!
... View more