what you want is join two search whit the same field/value ?
something like this?
index=apic component=faultInst | eval cT = strptime(created, "%Y-%m-%dT%H:%M:%S.%3N") | eval early = relative_time(cT,"-1m") | eval c1 = strftime(early,"%m/%d/%Y:%H:%M")| table c1 | join c1 [ index=apic component=aaaModLR |eval created=c1 | table created,affected, c1]
http://docs.splunk.com/File:Join.png
... View more