<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to combine multiple queries into one? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-combine-multiple-queries-into-one/m-p/444665#M167634</link>
    <description>&lt;P&gt;Try this!&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; index=some_index sourcetype=some_source host=*host*  (span_name=SomeSpanName1 OR span_name=SomeSpanName2 OR span_name=SomeSpanName3 OR span_name=SomeSpanName4)
| eval duration=span_duration/1000 | stats p99(duration)  by span_name
| transpose header_field=span_name| fields - column
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Thu, 06 Sep 2018 09:08:39 GMT</pubDate>
    <dc:creator>HiroshiSatoh</dc:creator>
    <dc:date>2018-09-06T09:08:39Z</dc:date>
    <item>
      <title>How to combine multiple queries into one?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-combine-multiple-queries-into-one/m-p/444663#M167632</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I have multiple queries with small differences, is it possible to combine them?&lt;/P&gt;

&lt;P&gt;Here is example:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=some_index sourcetype=some_source host=*host* (span_name=SomeSpanName1)  | eval duration=span_duration/1000 | stats p99(duration)

index=some_index sourcetype=some_source host=*host* (span_name=SomeSpanName2 OR span_name=SomeSpanName3)  | eval duration=span_duration/1000 | stats p99(duration)

index=some_index sourcetype=some_source host=*host* (span_name=SomeSpanName4)  | eval duration=span_duration/1000 | stats p99(duration)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The result of each query is only one column &lt;CODE&gt;p99(duration)&lt;/CODE&gt; with value.&lt;/P&gt;

&lt;P&gt;Is it possible to combine these queries and get a result with three columns with different names (I need to know  the correspondence of each column to the condition)?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Sep 2018 08:18:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-combine-multiple-queries-into-one/m-p/444663#M167632</guid>
      <dc:creator>vintik</dc:creator>
      <dc:date>2018-09-06T08:18:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to combine multiple queries into one?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-combine-multiple-queries-into-one/m-p/444664#M167633</link>
      <description>&lt;P&gt;Hi @vintik,&lt;/P&gt;

&lt;P&gt;Please try below query.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=some_index sourcetype=some_source host=*host* (span_name=SomeSpanName1 OR span_name=SomeSpanName2 OR span_name=SomeSpanName3 OR span_name=SomeSpanName4)
| eval duration=span_duration/1000
| stats p99(eval(if(span_name="SomeSpanName1",duration,0))) AS p99_Span1, p99(eval(if(span_name="SomeSpanName2" OR span_name="SomeSpanName3",duration,0))) AS p99_Span2_3, p99(eval(if(span_name="SomeSpanName4",duration,0))) AS p99_Span4  
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I have created run anywhere search as below which gives me correct result.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| makeresults | eval span_name="SomeSpanName1", span_duration="1001"
| append [ makeresults | eval span_name="SomeSpanName2", span_duration="2001" ]
| append [ makeresults | eval span_name="SomeSpanName3", span_duration="3001" ]
| append [ makeresults | eval span_name="SomeSpanName4", span_duration="4001" ]
| eval duration=span_duration/1000
| stats p99(eval(if(span_name="SomeSpanName1",duration,0))) AS p99_Span1, p99(eval(if(span_name="SomeSpanName2" OR span_name="SomeSpanName3",duration,0))) AS p99_Span2_3, p99(eval(if(span_name="SomeSpanName4",duration,0))) AS p99_Span4
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 06 Sep 2018 08:35:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-combine-multiple-queries-into-one/m-p/444664#M167633</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2018-09-06T08:35:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to combine multiple queries into one?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-combine-multiple-queries-into-one/m-p/444665#M167634</link>
      <description>&lt;P&gt;Try this!&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; index=some_index sourcetype=some_source host=*host*  (span_name=SomeSpanName1 OR span_name=SomeSpanName2 OR span_name=SomeSpanName3 OR span_name=SomeSpanName4)
| eval duration=span_duration/1000 | stats p99(duration)  by span_name
| transpose header_field=span_name| fields - column
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 06 Sep 2018 09:08:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-combine-multiple-queries-into-one/m-p/444665#M167634</guid>
      <dc:creator>HiroshiSatoh</dc:creator>
      <dc:date>2018-09-06T09:08:39Z</dc:date>
    </item>
  </channel>
</rss>

