I have to add 2 searches. Each search's output is FileName and Time....and I have to create a graph with the 2 types of file counts against time.
I used the search below:
index=MyIndex ( (filename=PNASC.HRBDT.*) OR (filename=PNASC.MBRETRAN.*) ) status=1 |rename filename as FileNameA, _time as Time | table "FileNameA" status
append status [ search index=MyIndex ( (filename=CFCF.GRP*.txt) OR (filename=CFCF.MBR*.txt) ) status=1 |rename filename as "FileNameB", _time as Time |table "FileNameB" status
] timechart span=1d count("FileNameA") count("FileNameB")
but getting errors
tried Join too, but I don't have any common field with same values.
Try like this (assuming all data lies in same MyIndex)
index=MyIndex filename=PNASC.HRBDT.* OR filename=PNASC.MBRETRAN.* OR filename=CFCF.GRP*.txt OR filename=CFCF.MBR*.txt status=1 | eval Type=if(like(filename,"PNASC.HRBDT.%") OR like(filename,"PNASC.MBRETRAN.%"),"FileNameA","FileNameB")
| timechart span=1d count by Type
Try like this (assuming all data lies in same MyIndex)
index=MyIndex filename=PNASC.HRBDT.* OR filename=PNASC.MBRETRAN.* OR filename=CFCF.GRP*.txt OR filename=CFCF.MBR*.txt status=1 | eval Type=if(like(filename,"PNASC.HRBDT.%") OR like(filename,"PNASC.MBRETRAN.%"),"FileNameA","FileNameB")
| timechart span=1d count by Type
Worked like a charm ...thanks