<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: three search in same page with alert and time span=3 month in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/three-search-in-same-page-with-alert-and-time-span-3-month/m-p/367983#M108472</link>
    <description>&lt;P&gt;you need to provide more information&lt;BR /&gt;
please give examples of the events you're searching and explain what counts you want &lt;/P&gt;</description>
    <pubDate>Tue, 20 Mar 2018 12:50:43 GMT</pubDate>
    <dc:creator>kmaron</dc:creator>
    <dc:date>2018-03-20T12:50:43Z</dc:date>
    <item>
      <title>three search in same page with alert and time span=3 month</title>
      <link>https://community.splunk.com/t5/Splunk-Search/three-search-in-same-page-with-alert-and-time-span-3-month/m-p/367979#M108468</link>
      <description>&lt;P&gt;i want to do three different search in same page for time span is 3 month&lt;BR /&gt;
i need a alert to be configured&lt;/P&gt;</description>
      <pubDate>Tue, 20 Mar 2018 09:52:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/three-search-in-same-page-with-alert-and-time-span-3-month/m-p/367979#M108468</guid>
      <dc:creator>logloganathan</dc:creator>
      <dc:date>2018-03-20T09:52:35Z</dc:date>
    </item>
    <item>
      <title>Re: three search in same page with alert and time span=3 month</title>
      <link>https://community.splunk.com/t5/Splunk-Search/three-search-in-same-page-with-alert-and-time-span-3-month/m-p/367980#M108469</link>
      <description>&lt;P&gt;any update?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Mar 2018 10:50:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/three-search-in-same-page-with-alert-and-time-span-3-month/m-p/367980#M108469</guid>
      <dc:creator>logloganathan</dc:creator>
      <dc:date>2018-03-20T10:50:12Z</dc:date>
    </item>
    <item>
      <title>Re: three search in same page with alert and time span=3 month</title>
      <link>https://community.splunk.com/t5/Splunk-Search/three-search-in-same-page-with-alert-and-time-span-3-month/m-p/367981#M108470</link>
      <description>&lt;P&gt;Can you please provide more information.&lt;BR /&gt;
What are you searching for? What are your searches? Is this a dashboard? What do you want to alert on?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Mar 2018 12:29:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/three-search-in-same-page-with-alert-and-time-span-3-month/m-p/367981#M108470</guid>
      <dc:creator>kmaron</dc:creator>
      <dc:date>2018-03-20T12:29:29Z</dc:date>
    </item>
    <item>
      <title>Re: three search in same page with alert and time span=3 month</title>
      <link>https://community.splunk.com/t5/Splunk-Search/three-search-in-same-page-with-alert-and-time-span-3-month/m-p/367982#M108471</link>
      <description>&lt;P&gt;no its not dashboard i want to do search to find 3 data count..all are different.&lt;BR /&gt;
is there any way to do that apart from dashboard?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Mar 2018 12:48:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/three-search-in-same-page-with-alert-and-time-span-3-month/m-p/367982#M108471</guid>
      <dc:creator>logloganathan</dc:creator>
      <dc:date>2018-03-20T12:48:18Z</dc:date>
    </item>
    <item>
      <title>Re: three search in same page with alert and time span=3 month</title>
      <link>https://community.splunk.com/t5/Splunk-Search/three-search-in-same-page-with-alert-and-time-span-3-month/m-p/367983#M108472</link>
      <description>&lt;P&gt;you need to provide more information&lt;BR /&gt;
please give examples of the events you're searching and explain what counts you want &lt;/P&gt;</description>
      <pubDate>Tue, 20 Mar 2018 12:50:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/three-search-in-same-page-with-alert-and-time-span-3-month/m-p/367983#M108472</guid>
      <dc:creator>kmaron</dc:creator>
      <dc:date>2018-03-20T12:50:43Z</dc:date>
    </item>
    <item>
      <title>Re: three search in same page with alert and time span=3 month</title>
      <link>https://community.splunk.com/t5/Splunk-Search/three-search-in-same-page-with-alert-and-time-span-3-month/m-p/367984#M108473</link>
      <description>&lt;P&gt;yes..&lt;BR /&gt;
index=A sourectype=B "XXX" | stats count by XXX&lt;BR /&gt;
index=A sourectype=B "YYY" | stats count by YYY&lt;BR /&gt;
index=A sourectype=B "ZZZ" | stats count by ZZZ&lt;/P&gt;

&lt;P&gt;i want these three table in one page and alert configured for this&lt;/P&gt;</description>
      <pubDate>Tue, 20 Mar 2018 13:00:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/three-search-in-same-page-with-alert-and-time-span-3-month/m-p/367984#M108473</guid>
      <dc:creator>logloganathan</dc:creator>
      <dc:date>2018-03-20T13:00:14Z</dc:date>
    </item>
    <item>
      <title>Re: three search in same page with alert and time span=3 month</title>
      <link>https://community.splunk.com/t5/Splunk-Search/three-search-in-same-page-with-alert-and-time-span-3-month/m-p/367985#M108474</link>
      <description>&lt;P&gt;Is your alert depend on output of 3 different searches? Can you share your searches and alert conditions ?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Mar 2018 13:01:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/three-search-in-same-page-with-alert-and-time-span-3-month/m-p/367985#M108474</guid>
      <dc:creator>p_gurav</dc:creator>
      <dc:date>2018-03-20T13:01:00Z</dc:date>
    </item>
    <item>
      <title>Re: three search in same page with alert and time span=3 month</title>
      <link>https://community.splunk.com/t5/Splunk-Search/three-search-in-same-page-with-alert-and-time-span-3-month/m-p/367986#M108475</link>
      <description>&lt;P&gt;did you try using&lt;CODE&gt;append&lt;/CODE&gt; command?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=A sourectype=B "XXX" | stats count by XXX |append [search index=A sourectype=B "YYY" | stats count by YYY] | append [search index=A sourectype=B "ZZZ" | stats count by ZZZ]
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 20 Mar 2018 13:05:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/three-search-in-same-page-with-alert-and-time-span-3-month/m-p/367986#M108475</guid>
      <dc:creator>p_gurav</dc:creator>
      <dc:date>2018-03-20T13:05:18Z</dc:date>
    </item>
    <item>
      <title>Re: three search in same page with alert and time span=3 month</title>
      <link>https://community.splunk.com/t5/Splunk-Search/three-search-in-same-page-with-alert-and-time-span-3-month/m-p/367987#M108476</link>
      <description>&lt;P&gt;thanks..please post this in answer tab&lt;/P&gt;</description>
      <pubDate>Tue, 20 Mar 2018 15:05:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/three-search-in-same-page-with-alert-and-time-span-3-month/m-p/367987#M108476</guid>
      <dc:creator>logloganathan</dc:creator>
      <dc:date>2018-03-20T15:05:26Z</dc:date>
    </item>
    <item>
      <title>Re: three search in same page with alert and time span=3 month</title>
      <link>https://community.splunk.com/t5/Splunk-Search/three-search-in-same-page-with-alert-and-time-span-3-month/m-p/367988#M108477</link>
      <description>&lt;P&gt;@logloganathan you should explore the &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Multisearch"&gt;multisearch&lt;/A&gt; command which is not restricted by sub-search limitations&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| multisearch 
    [search index=A sourcetype=B XXX=*]
    [search index=A sourcetype=B YYY=*]
    [search index=A sourcetype=B ZZZ=*]
| stats count by XXX YYY ZZZ
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;However, Splunk has numerous &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Search/Abouteventcorrelation"&gt;event grouping and correlation&lt;/A&gt; mechanisms based on the Use Cases and we can not always apply any one of the correlation mechanism for all the scenarios.&lt;/P&gt;

&lt;P&gt;So you should elaborate on what exactly is your use case. If you are planning to pull 3 months of data to create an alert, could you rely on summary indexing instead? Community would be able to assist you better you add more context to your questions like what is your use case, what does your data look like? What have you tried so far and what does not seem to work?&lt;/P&gt;

&lt;P&gt;I dont think a doctor should treat patient based on hunch rather the cure should be based upon symptoms!!! So for us to help you better add as much of details as possible to your questions &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Mar 2018 18:26:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/three-search-in-same-page-with-alert-and-time-span-3-month/m-p/367988#M108477</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2018-03-20T18:26:24Z</dc:date>
    </item>
    <item>
      <title>Re: three search in same page with alert and time span=3 month</title>
      <link>https://community.splunk.com/t5/Splunk-Search/three-search-in-same-page-with-alert-and-time-span-3-month/m-p/367989#M108478</link>
      <description>&lt;P&gt;I can provide only example use cases..i can't provide organization data..i already provided example query I just need output for that and i got it from you..thanks for that&lt;/P&gt;</description>
      <pubDate>Wed, 21 Mar 2018 07:10:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/three-search-in-same-page-with-alert-and-time-span-3-month/m-p/367989#M108478</guid>
      <dc:creator>logloganathan</dc:creator>
      <dc:date>2018-03-21T07:10:58Z</dc:date>
    </item>
    <item>
      <title>Re: three search in same page with alert and time span=3 month</title>
      <link>https://community.splunk.com/t5/Splunk-Search/three-search-in-same-page-with-alert-and-time-span-3-month/m-p/367990#M108479</link>
      <description>&lt;P&gt;I am glad you are able to resolve the issue that you are facing. Yes we understand that organization data can not be published on public forums, however, usually request here on Splunk Answers is for mocked/anonymized data. In fact most of the times if sensitive information is posted accidentally by folks, community moderators do reach out to them for masking/anonymizing the same.&lt;/P&gt;

&lt;P&gt;Following is an example of anonymized data in similar format to how original event might have triggered in the system, but without revealing any sensitive information.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;2017/01/12 08:09:04.325 AM [ERROR] Login failed for abc@def.com on server servername01@domain.com.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Having said that I am still curious on the use case for pulling 3 months data for an alert. It is up to you whether you want to post the use case or not since your issue is already resolved! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Mar 2018 06:18:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/three-search-in-same-page-with-alert-and-time-span-3-month/m-p/367990#M108479</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2018-03-22T06:18:37Z</dc:date>
    </item>
  </channel>
</rss>

