hi,
index="idx_a" sourcetype IN ("logs") component=* logpoint=request-in
| table transaction-id,timestamp-in| append
[ search index="idx_a" sourcetype IN ("logs") component=* logpoint=response-out
| table timestamp-out]
| table transaction-id,timestamp-in,timestamp-out
In my last query, timestamp-out is blank.
Can anyone please help?
Are you trying to do a table of transaction-id,timestamp-in,timestamp-out with proper results,
Use the join command like this
index="idx_a" sourcetype IN ("logs") component= logpoint=request-in
| table transaction-id,timestamp-in| join transaction-id
[ search index="idx_a" sourcetype IN ("logs") component= logpoint=response-out
| table timestamp-out, transaction-id]
| table transaction-id,timestamp-in,timestamp-out
Only Join will map the transaction id with respective timestamp-in & timestamp-out.
Appendcols & append commands are used to append the results from main search to sub search, which is not a table of ordered correctly mapped data
Thanks
Are you trying to do a table of transaction-id,timestamp-in,timestamp-out with proper results,
Use the join command like this
index="idx_a" sourcetype IN ("logs") component= logpoint=request-in
| table transaction-id,timestamp-in| join transaction-id
[ search index="idx_a" sourcetype IN ("logs") component= logpoint=response-out
| table timestamp-out, transaction-id]
| table transaction-id,timestamp-in,timestamp-out
Only Join will map the transaction id with respective timestamp-in & timestamp-out.
Appendcols & append commands are used to append the results from main search to sub search, which is not a table of ordered correctly mapped data
Thanks
try |appendcols
instead of |append