Hi,
Wondering if someone could help me here, I'm trying to join two tstats searches together.
I basically want to get a result 120 minutes ago and a result for the last 60 minutes based on hosts.
Here is the search:
| tstats summariesonly=t prestats=t count as old from datamodel=Web WHERE earliest=-120m latest=-60m by host | stats count as old by host | tstats summariesonly=t prestats=t append=t count as new from datamodel=Web WHERE earliest=-60m latest=now by host | stats count as new by host
Any idea why this doesn't work?
Thanks!
Try like this
| tstats summariesonly=t prestats=t count from datamodel=Web WHERE earliest=-120m@m latest=@m by host _time span=1m | eval Period=if(_time>relative_time(now(),"-60m@m"),"New","Old") | chart sum(count) over host by Period
Try like this
| tstats summariesonly=t prestats=t count from datamodel=Web WHERE earliest=-120m@m latest=@m by host _time span=1m | eval Period=if(_time>relative_time(now(),"-60m@m"),"New","Old") | chart sum(count) over host by Period
Thanks for that.
Afraid it doesn't work. sum(count) has no values, but I know there are numbers there because I can do it without using the datamodel.
Maybe this will help https://answers.splunk.com/answers/215346/best-practices-to-join-two-child-objects-of-a-data.html ?
cheers, MuS
Managed to fix it by,
| tstats summariesonly=t prestats=t count from datamodel=Matin WHERE earliest=-120m@m latest=@m by host _time span=1m | eval Period=if(_time>relative_time(now(),"-60m@m"),"New","Old") | chart count over host by Period
Thanks!!!!!