I'm searching blocked events from the firewall and Palo Alto logs and would like to add a line to show the Total of the two combined. I'm having trouble adding the line showing the total of the counts for the two individual indexes.
Current search:
index=firewalls OR index=paloalto action=blocked | stats count as "Blocked Events" by index
I would like the results to look like
firewalls 10
paloalto 25
total 35
You should use addcoltotals
It will look something like this
| addcoltotals label=Total labelfield=status
You should use addcoltotals
It will look something like this
| addcoltotals label=Total labelfield=status
Thanks.. this works