<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How To Join Results From Multiple Searches in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-To-Join-Results-From-Multiple-Searches/m-p/324993#M161386</link>
    <description>&lt;P&gt;Give this a try&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;host=serverName sourcetype=http_access_log | eventstats stdev(ResponseTime) as TotalStdDev | table _time host ResponseTime TotalStdDev
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Tue, 11 Apr 2017 21:57:48 GMT</pubDate>
    <dc:creator>somesoni2</dc:creator>
    <dc:date>2017-04-11T21:57:48Z</dc:date>
    <item>
      <title>How To Join Results From Multiple Searches</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-To-Join-Results-From-Multiple-Searches/m-p/324991#M161384</link>
      <description>&lt;P&gt;I'm trying to create a simple control chart (where I show a line 3 standard deviations away from the mean).  I just need to calculate what the standard deviation is for my entire set of data, multiply by 3 and plot the line along with my data. &lt;/P&gt;

&lt;P&gt;Originally I tried to use a pivot because I used DataSets for speed but eventually gave up.&lt;/P&gt;

&lt;P&gt;Now I'm trying the search syntax and it appears like the "append" command is what I need.  &lt;/P&gt;

&lt;P&gt;host=serverName sourcetype=http_access_log | append [search host=serverName sourcetype=http_access_log | stats stdev(ResponseTime) as TotalStdDev] | table _time host ResponseTime TotalStdDev&lt;/P&gt;

&lt;P&gt;I'm just trying to generate a simple table to start with that has the TotalStdDev copied for each entry.  Maybe then I can start aggregating based on days.  But I can't even get the total standard deviation for the entire data set into my table.&lt;/P&gt;

&lt;P&gt;Any suggestions out there?&lt;BR /&gt;
Thanks,&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 13:38:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-To-Join-Results-From-Multiple-Searches/m-p/324991#M161384</guid>
      <dc:creator>theironcook</dc:creator>
      <dc:date>2020-09-29T13:38:36Z</dc:date>
    </item>
    <item>
      <title>Re: How To Join Results From Multiple Searches</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-To-Join-Results-From-Multiple-Searches/m-p/324992#M161385</link>
      <description>&lt;P&gt;Hi theironcook,&lt;/P&gt;

&lt;P&gt;take a look at this answer &lt;A href="https://answers.splunk.com/answers/129424/how-to-compare-fields-over-multiple-sourcetypes-without-join-append-or-use-of-subsearches.html"&gt;https://answers.splunk.com/answers/129424/how-to-compare-fields-over-multiple-sourcetypes-without-join-append-or-use-of-subsearches.html&lt;/A&gt; it provides some examples how it can be done. The answer is not limited to two source ... it can be applied to endless events.&lt;/P&gt;

&lt;P&gt;Hope this helps ...&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2017 21:56:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-To-Join-Results-From-Multiple-Searches/m-p/324992#M161385</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2017-04-11T21:56:12Z</dc:date>
    </item>
    <item>
      <title>Re: How To Join Results From Multiple Searches</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-To-Join-Results-From-Multiple-Searches/m-p/324993#M161386</link>
      <description>&lt;P&gt;Give this a try&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;host=serverName sourcetype=http_access_log | eventstats stdev(ResponseTime) as TotalStdDev | table _time host ResponseTime TotalStdDev
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 11 Apr 2017 21:57:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-To-Join-Results-From-Multiple-Searches/m-p/324993#M161386</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2017-04-11T21:57:48Z</dc:date>
    </item>
    <item>
      <title>Re: How To Join Results From Multiple Searches</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-To-Join-Results-From-Multiple-Searches/m-p/324994#M161387</link>
      <description>&lt;P&gt;Nice!  Thanks MuS and somesoni2!&lt;BR /&gt;
I went with the eventstats option.  It works beautifully.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2017 22:20:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-To-Join-Results-From-Multiple-Searches/m-p/324994#M161387</guid>
      <dc:creator>theironcook</dc:creator>
      <dc:date>2017-04-11T22:20:08Z</dc:date>
    </item>
  </channel>
</rss>

