<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Different sourcetypes in a single search in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Different-sourcetypes-in-a-single-search/m-p/110133#M23136</link>
    <description>&lt;PRE&gt;&lt;CODE&gt;(sourcetype=st_1 OR sourcetype=st_2) id=id_to_search_for
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Tue, 19 May 2015 13:26:47 GMT</pubDate>
    <dc:creator>mikebd</dc:creator>
    <dc:date>2015-05-19T13:26:47Z</dc:date>
    <item>
      <title>Different sourcetypes in a single search</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Different-sourcetypes-in-a-single-search/m-p/110131#M23134</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have to search for data from two different sourcetypes. There is a common field in both the sourcetypes called id. So When i search using this id it should return the corresponding events  from both the sourcetypes. It sould searchin both and return the events if the id exists. Can anyone suggest how to do this? Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2015 06:04:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Different-sourcetypes-in-a-single-search/m-p/110131#M23134</guid>
      <dc:creator>vaishnavi07</dc:creator>
      <dc:date>2015-05-14T06:04:38Z</dc:date>
    </item>
    <item>
      <title>Re: Different sourcetypes in a single search</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Different-sourcetypes-in-a-single-search/m-p/110132#M23135</link>
      <description>&lt;P&gt;Hi vaishnavi07,&lt;/P&gt;

&lt;P&gt;For sure I can suggest how to do this; take a look at this answer here : &lt;A href="http://answers.splunk.com/answers/129424/how-to-compare-fields-over-multiple-sourcetypes-without-join-append-or-use-of-subsearches.html"&gt;http://answers.splunk.com/answers/129424/how-to-compare-fields-over-multiple-sourcetypes-without-join-append-or-use-of-subsearches.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;It will explain everything to you....&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2015 06:15:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Different-sourcetypes-in-a-single-search/m-p/110132#M23135</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2015-05-14T06:15:29Z</dc:date>
    </item>
    <item>
      <title>Re: Different sourcetypes in a single search</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Different-sourcetypes-in-a-single-search/m-p/110133#M23136</link>
      <description>&lt;PRE&gt;&lt;CODE&gt;(sourcetype=st_1 OR sourcetype=st_2) id=id_to_search_for
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 19 May 2015 13:26:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Different-sourcetypes-in-a-single-search/m-p/110133#M23136</guid>
      <dc:creator>mikebd</dc:creator>
      <dc:date>2015-05-19T13:26:47Z</dc:date>
    </item>
  </channel>
</rss>

