You need the map
command, like this:
first search that generates a list of events that have the "_time" values you need | map search = "search earliest>(_time-60) latest<(time+60) some other search"
You can also use the FOREACH
command.
I am trying this..Meanwhile could you please tell if it is possible:
1st query output:
date_hour date_mday
4 15
2nd query output using hour and day of 1st query ouput
host counter avg(Value)
1552 % Processor Time 20.611920
I want
date_hour date_mday host counter avg(Value)
4 15 ms.. .... ...
OK, I think you are asking for something different than is implied by your original text. It sounds like you are trying to do a join
(merge) by host
. If so, try this:
(first query here | eval datehour=date_hour | eval datemday=date_mday) OR (second query here) | stats avg(Value) values(counter) AS counter values(datehour) AS datehour values(datemday) AS datemday by host