<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to line up 2 reports in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-line-up-2-reports/m-p/527145#M148794</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;: I'm trying to combine 2 reports into 1 and schedule one report. The first report has weekly values where the second has Yearly values with different columns&lt;/P&gt;</description>
    <pubDate>Thu, 29 Oct 2020 17:02:44 GMT</pubDate>
    <dc:creator>iamsplunker</dc:creator>
    <dc:date>2020-10-29T17:02:44Z</dc:date>
    <item>
      <title>How to line up 2 reports</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-line-up-2-reports/m-p/526526#M148603</link>
      <description>&lt;P&gt;Hello Splunk Community,&lt;/P&gt;&lt;P&gt;I have 2 reports trying to combine into 1. The fields are different to each other. Say Report 1 has field1,field2,field3,field4,field5 and Report2 has field6, field,7, field8,field9&lt;/P&gt;&lt;P&gt;Report 1 uses weekly time range earliest=-1w@w latest=@w1&lt;/P&gt;&lt;P&gt;Report 2 uses Year to date time range earliest=@y latest=@w1&lt;/P&gt;&lt;P&gt;I tried using append,appedcols and join but the values are messing up and not lined up together&lt;/P&gt;&lt;P&gt;Please help&lt;/P&gt;</description>
      <pubDate>Mon, 26 Oct 2020 19:51:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-line-up-2-reports/m-p/526526#M148603</guid>
      <dc:creator>iamsplunker</dc:creator>
      <dc:date>2020-10-26T19:51:36Z</dc:date>
    </item>
    <item>
      <title>Re: How to line up 2 reports</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-line-up-2-reports/m-p/526597#M148631</link>
      <description>&lt;P&gt;What were you hoping to achieve?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Oct 2020 08:06:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-line-up-2-reports/m-p/526597#M148631</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-10-27T08:06:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to line up 2 reports</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-line-up-2-reports/m-p/527145#M148794</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;: I'm trying to combine 2 reports into 1 and schedule one report. The first report has weekly values where the second has Yearly values with different columns&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2020 17:02:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-line-up-2-reports/m-p/527145#M148794</guid>
      <dc:creator>iamsplunker</dc:creator>
      <dc:date>2020-10-29T17:02:44Z</dc:date>
    </item>
    <item>
      <title>Re: How to line up 2 reports</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-line-up-2-reports/m-p/527155#M148797</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/223385"&gt;@iamsplunker&lt;/a&gt;&amp;nbsp;You will need to be more specific. Without seeing your queries I will have to guess: your columns don't line up because they are different names; your rows probably don't line up because they are different dates? Do you want to line the columns up or the rows? If it is the columns, you would need to rename the fields from one query so that they match the fields from the other query. If you want the rows to line up, you will probably have to adjust the dates so that they are the same, they are possibly timestamped with the beginning of the period rather than the end.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2020 18:33:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-line-up-2-reports/m-p/527155#M148797</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-10-29T18:33:59Z</dc:date>
    </item>
  </channel>
</rss>

