<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: append command deletes values from search in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/append-command-deletes-values-from-search/m-p/426265#M173455</link>
    <description>&lt;P&gt;earliest=-10m latest=now index=_internal source=&lt;EM&gt;metrics.log&lt;/EM&gt; fwdType!="uf" |head 2&lt;BR /&gt;
|append  [|search earliest=-10m latest=now index=_internal source=&lt;EM&gt;metrics.log&lt;/EM&gt; fwdType="uf"  |head 1  ]&lt;BR /&gt;
|table hostname ,version&lt;BR /&gt;
not possible to be issue as only 1 row.&lt;BR /&gt;
Plus the missing data is most of time from the first search ,though sometime from both are missing.&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 22:56:53 GMT</pubDate>
    <dc:creator>net1993</dc:creator>
    <dc:date>2020-09-29T22:56:53Z</dc:date>
    <item>
      <title>append command deletes values from search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/append-command-deletes-values-from-search/m-p/426263#M173453</link>
      <description>&lt;P&gt;Hi&lt;BR /&gt;
using append to add result to search , values dissapears from my main search and drives me crazy.&lt;BR /&gt;
The result is per search basis, meaning 1 time execute -&amp;gt; Null values, 2nd run -&amp;gt; ok - 3rd Null...&lt;BR /&gt;
100% problem is from append. &lt;BR /&gt;
Total non-sense and more than 7 hours analyzing.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jan 2019 22:28:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/append-command-deletes-values-from-search/m-p/426263#M173453</guid>
      <dc:creator>net1993</dc:creator>
      <dc:date>2019-01-23T22:28:38Z</dc:date>
    </item>
    <item>
      <title>Re: append command deletes values from search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/append-command-deletes-values-from-search/m-p/426264#M173454</link>
      <description>&lt;P&gt;There is a limit on number of events returned from sub-search, could be because of that.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jan 2019 00:30:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/append-command-deletes-values-from-search/m-p/426264#M173454</guid>
      <dc:creator>Vijeta</dc:creator>
      <dc:date>2019-01-24T00:30:18Z</dc:date>
    </item>
    <item>
      <title>Re: append command deletes values from search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/append-command-deletes-values-from-search/m-p/426265#M173455</link>
      <description>&lt;P&gt;earliest=-10m latest=now index=_internal source=&lt;EM&gt;metrics.log&lt;/EM&gt; fwdType!="uf" |head 2&lt;BR /&gt;
|append  [|search earliest=-10m latest=now index=_internal source=&lt;EM&gt;metrics.log&lt;/EM&gt; fwdType="uf"  |head 1  ]&lt;BR /&gt;
|table hostname ,version&lt;BR /&gt;
not possible to be issue as only 1 row.&lt;BR /&gt;
Plus the missing data is most of time from the first search ,though sometime from both are missing.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 22:56:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/append-command-deletes-values-from-search/m-p/426265#M173455</guid>
      <dc:creator>net1993</dc:creator>
      <dc:date>2020-09-29T22:56:53Z</dc:date>
    </item>
    <item>
      <title>Re: append command deletes values from search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/append-command-deletes-values-from-search/m-p/426266#M173456</link>
      <description>&lt;P&gt;Can you also try join/ appendcols and other commands.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jan 2019 07:33:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/append-command-deletes-values-from-search/m-p/426266#M173456</guid>
      <dc:creator>ashmaind</dc:creator>
      <dc:date>2019-01-29T07:33:58Z</dc:date>
    </item>
    <item>
      <title>Re: append command deletes values from search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/append-command-deletes-values-from-search/m-p/426267#M173457</link>
      <description>&lt;P&gt;the same behaviour is with union&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jan 2019 07:38:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/append-command-deletes-values-from-search/m-p/426267#M173457</guid>
      <dc:creator>net1993</dc:creator>
      <dc:date>2019-01-29T07:38:11Z</dc:date>
    </item>
    <item>
      <title>Re: append command deletes values from search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/append-command-deletes-values-from-search/m-p/426268#M173458</link>
      <description>&lt;P&gt;so far is defect - splunk&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jan 2019 07:38:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/append-command-deletes-values-from-search/m-p/426268#M173458</guid>
      <dc:creator>net1993</dc:creator>
      <dc:date>2019-01-29T07:38:29Z</dc:date>
    </item>
  </channel>
</rss>

