I have a
SEARCH-1
Which Gives results like
-time column1 column2
I want to run a secondary search for each value of _time and add a column3 added to the existing columns in the result above.
-time column1 column2 column3
I am trying something like this. My old columns get lost in the process. And the number of results are also less.
index=abc sourcetype=sitescopev2log | timechart avg(Availability) by columns | map search="search index=xyz sourcetype=xyz_st | stats count as column3"
Like this:
index=abc sourcetype=sitescopev2log | timechart avg(Availability) BY columns
| append [index=xyz sourcetype=xyz_st | timechart count AS column3]
| timechart avg(*) AS *