Splunk Search

How to marge two in depended query result depending on parameter

snehalk
Communicator

Hello All,

I have the requirement where i need to marge two search query values depending on parameter.

Example:

Result of Query  1: 
ID  Email   Status
 1  xyz@abc        Pass

 2  dd@fd         Fail

Result Query 2 
 ID      Email            Status
1       xyz@abc      Fail

 2  dd@fd         Fail

What i want as final result

Final Query [ query 1 + query 2 ]
     ID      Email            Status
    1       xyz@abc      Fail

     2  dd@fd         Fail

Because the Id with 1 and email id with xyz@abc failed in second result .

I have used append and appendcols but its not working,.

So can any one help me on this?

Thanks!!

0 Karma
1 Solution

snehalk
Communicator

Hi All,

I got the answer for this problem. the query is as follow.

search query 1 | stats count by  ID,Email,Status1 | appendcols [search query 2 | stats count by  ID,Email,Status2 ] | eval finalstatus=if ( Status1= Pass AND Status2= Pass, "Pass", Fail) | stats count by finalstatus 

View solution in original post

0 Karma

snehalk
Communicator

Hi All,

I got the answer for this problem. the query is as follow.

search query 1 | stats count by  ID,Email,Status1 | appendcols [search query 2 | stats count by  ID,Email,Status2 ] | eval finalstatus=if ( Status1= Pass AND Status2= Pass, "Pass", Fail) | stats count by finalstatus 
0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...