<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Combine 3 queries into tabular form for export to .csv in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Combine-3-queries-into-tabular-form-for-export-to-csv/m-p/540451#M152901</link>
    <description>&lt;P&gt;This may help...&lt;/P&gt;&lt;P&gt;Query 1 | appendcols [ search Query2] | appendcols [search query3]&lt;/P&gt;&lt;P&gt;e.g:&amp;nbsp; index=_internal | stats count as col1 | appendcols [search index=_introspection | stats count as col2] | appendcols [search index=_audit | stats count as col3]&lt;/P&gt;</description>
    <pubDate>Thu, 18 Feb 2021 22:42:25 GMT</pubDate>
    <dc:creator>saravanan90</dc:creator>
    <dc:date>2021-02-18T22:42:25Z</dc:date>
    <item>
      <title>Combine 3 queries into tabular form for export to .csv</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Combine-3-queries-into-tabular-form-for-export-to-csv/m-p/540435#M152894</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;Need some assistance combining 3 queries in tabular form so I can export them to a lookup table.&lt;BR /&gt;I'm also trying to add a date range&lt;BR /&gt;&lt;SPAN&gt;Example - On 2021-02-18 morning we report metrics from&amp;nbsp;&amp;nbsp;2021-02-16 5:00 PM to&amp;nbsp;2021-02-17 5:00 PM&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Q1:&lt;BR /&gt;index=tst1 sourcetype IN (tst2, tst4, tst5) source IN ("/opt/performance.log", "/opt/formance.log", "/opt/test.log") | fields TRAN_TYPE, respTime, TRAN_TIME_MS |stats count as Total, count(eval(TRAN_TIME_MS&amp;lt;=3000)) as Total_Under_3sec1 ,count(eval(respTime&amp;lt;=3000)) as Total_Under_3sec2 | addtotals fieldname="Total_Under_3sec" Total_Under_3sec1 Total_Under_3sec2 | eval Perc = (Total_Under_3sec / Total)*100 |fields Perc&lt;/P&gt;&lt;P&gt;Q2:&lt;BR /&gt;index=tst2 sourcetype=tst2 PAGE_ID_WEIGHT=* TRAN_TYPE =* PAGE_ID=345 ACTION=GET | eval USER_ID=lower(USER_ID) | stats dc(USER_ID)&lt;/P&gt;&lt;P&gt;Q3:&lt;BR /&gt;index=tst3 sourcetype=test3 method=POST login=/tst3* user!=unauthenticated msgCode=302 | eval action=case(status==302,"Success") | stats dc(user)&lt;/P&gt;&lt;P&gt;Col1&amp;nbsp; &amp;nbsp; Col2&amp;nbsp; &amp;nbsp; &amp;nbsp; Col3&lt;BR /&gt;99&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 89&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;97&lt;/P&gt;&lt;P&gt;Any assistance is appreciated.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Feb 2021 19:59:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Combine-3-queries-into-tabular-form-for-export-to-csv/m-p/540435#M152894</guid>
      <dc:creator>shrogers</dc:creator>
      <dc:date>2021-02-18T19:59:53Z</dc:date>
    </item>
    <item>
      <title>Re: Combine 3 queries into tabular form for export to .csv</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Combine-3-queries-into-tabular-form-for-export-to-csv/m-p/540451#M152901</link>
      <description>&lt;P&gt;This may help...&lt;/P&gt;&lt;P&gt;Query 1 | appendcols [ search Query2] | appendcols [search query3]&lt;/P&gt;&lt;P&gt;e.g:&amp;nbsp; index=_internal | stats count as col1 | appendcols [search index=_introspection | stats count as col2] | appendcols [search index=_audit | stats count as col3]&lt;/P&gt;</description>
      <pubDate>Thu, 18 Feb 2021 22:42:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Combine-3-queries-into-tabular-form-for-export-to-csv/m-p/540451#M152901</guid>
      <dc:creator>saravanan90</dc:creator>
      <dc:date>2021-02-18T22:42:25Z</dc:date>
    </item>
    <item>
      <title>Re: Combine 3 queries into tabular form for export to .csv</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Combine-3-queries-into-tabular-form-for-export-to-csv/m-p/540528#M152928</link>
      <description>&lt;P&gt;Thank you for your quick response.&lt;/P&gt;&lt;P&gt;It works as expected.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Feb 2021 13:29:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Combine-3-queries-into-tabular-form-for-export-to-csv/m-p/540528#M152928</guid>
      <dc:creator>shrogers</dc:creator>
      <dc:date>2021-02-19T13:29:18Z</dc:date>
    </item>
    <item>
      <title>Re: Combine 3 queries into tabular form for export to .csv</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Combine-3-queries-into-tabular-form-for-export-to-csv/m-p/540578#M152939</link>
      <description>&lt;P&gt;Great !!&lt;/P&gt;&lt;P&gt;Appreciate if you could accept as solution....:)&lt;/P&gt;</description>
      <pubDate>Fri, 19 Feb 2021 21:15:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Combine-3-queries-into-tabular-form-for-export-to-csv/m-p/540578#M152939</guid>
      <dc:creator>saravanan90</dc:creator>
      <dc:date>2021-02-19T21:15:07Z</dc:date>
    </item>
  </channel>
</rss>

