how to join 2 different searches in a single index with different fileds and mapping them to the common field, please help :
My Problem Statement :
sourcetype="broker" host="g2m*" Participant_System_Information| top OSType
Result :
Windows 45741 90.932766
MacOSX 4176 8.301857
iOS 385 0.765377
sourcetype="broker" host="g2m*" createUpdateAttendeeResource| top ClientName
android 193 100.000000
Now i want to combine the above 2 quries and get the combined result of OSType and i used the below query and i am not getting the accurate count :
sourcetype="broker" host="g2m*" (createUpdateAttendeeResource OR Participant_System_Information)|rename OSType as OS| rename ClientName as OS| top OS
Windows 483 67.458101
android 177 24.720670
MacOSX 56 7.821229
I think for some reason "rename" is not working as expected when combing the query, please help.
Great , this seem to give the count that matches.
Thanks a lot !
I think that the last rename is always overwriting the previous value of the OS field and so you are losing information. Try this:
sourcetype="broker" host="g2m*" (createUpdateAttendeeResource OR Participant_System_Information) |
rename OSType as OS |
eval OS = if(OS=="" or isnull(OS),ClientName,OS) |
top OS