Hi,
I have the below 2 searches, which work fine. I need to put the output of both the searches in a single table so the whole data is displayed over ClusterName. Please let me know how I can achieve this.
sourcetype = aaa_sss* eventtype=* | chart values(eventtype) AS Events over clusterName |
clusterName=xxx | timechart span=1m count by eventtype | eval count = ceiling(count/16)
Is it like this?
※I do not consider performance etc.
sourcetype = aaa_sss* eventtype=* | chart values(eventtype) AS Events over clusterName
|map search="search clusterName=$clusterName$
|eval eventtype=\"$eventtype$\"|timechart span=1m count by eventtype|eval clusterName=\"$clusterName$\""
What the expected (sample) resulting table? (what columns? show some sample values)