Skip to main content

append

Description

Appends data obtained from a search within the append command to the main results.

Syntax

| append [ <subsearch> ] <subsearch-options>...

Required Arguments

ParameterSyntaxDescription
subsearch[<subsearch>]The query must be enclosed in square brackets and must start with a source designation (source, script, makeresults, etc.).

Optional Arguments

ParameterSyntaxDefaultDescription
maxtimemaxtime=6060 secondsMaximum query execution time in seconds.
maxoutmaxout=10000Maximum number of returned results.
timeouttimeout=600Maximum query execution time in seconds.

Query Examples

Example #1
source accessLogs
| append
[ source cli:myDb.myUsersData:10
| stats count by user ]
Example #2
source accessLogs qsize=1
| search user="aleksey" and message="Access granted"
| append
[ source radius_logs qsize=1
| search agent.id="5859c99d-8ac6-4adc-af94-a371d2a5cf28" and indextime >= "2020-11-12T14:18:28.038337Z" ]