I have a search like this:
search| stats count by errortype
which is quite simple and returns:
errortype count
1600 45
1234 60
Now I want to add in same chart a new column using the dedup command (that I already have and works), but filters a new result with less logs count. I would like to have something like:
errortype count newcount
How can I do it?
You could either do a | stats count dc(field) as distinct by errortype
or use appendcols
like this
.. | stats count by errortype | appendcols [ search ... | dedup field | stats count as distinct by errortype ]
You could either do a | stats count dc(field) as distinct by errortype
or use appendcols
like this
.. | stats count by errortype | appendcols [ search ... | dedup field | stats count as distinct by errortype ]
thanks budy, appendcols worked perfectly
@guillecasco Glad you found your answer through @sundareshr !
Since it has a working solution, don't forget to resolve the question by clicking "Accept" directly below sundareshr's post.