HIhi
why I have no resulys even if I merge 2 index even if I have results when I execute one or the other?
(index=ai-pe-* sourcetype="Perfmon:Mem OR index=ai-wmi-* sourcetype="WMI:Mem")
| fields host Value TotalPhysicalMemory
| eval FreeMemory = round(Value, 2). " MB"
| eval TotalMemory = round((TotalPhysicalMemory / 1024 / 1024), 2). " MB"
Your query currently gets interpreted as this:
(I'm also guessing there were *
s in the index names - use the code formatter tool 101010
to avoid the html renderer removing them)
index=ai-pe-* AND (sourcetype="Perfmon:Mem OR index=ai-wmi-*) AND sourcetype="WMI:Mem"
Instead you want:
(index=ai-pe-* AND sourcetype="Perfmon:Mem) OR (index=ai-wmi-* AND sourcetype="WMI:Mem")
You can leave the AND
s out - I just added them for clairty
Your query currently gets interpreted as this:
(I'm also guessing there were *
s in the index names - use the code formatter tool 101010
to avoid the html renderer removing them)
index=ai-pe-* AND (sourcetype="Perfmon:Mem OR index=ai-wmi-*) AND sourcetype="WMI:Mem"
Instead you want:
(index=ai-pe-* AND sourcetype="Perfmon:Mem) OR (index=ai-wmi-* AND sourcetype="WMI:Mem")
You can leave the AND
s out - I just added them for clairty
you are right, thanks