<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Combine/Merge results from Exim Search in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Combine-Merge-results-from-Exim-Search/m-p/169867#M186276</link>
    <description>&lt;P&gt;Could be more specific on what do you mean by merging/combining the results? Probably the output/table you're looking for.&lt;/P&gt;</description>
    <pubDate>Fri, 28 Feb 2014 14:05:54 GMT</pubDate>
    <dc:creator>somesoni2</dc:creator>
    <dc:date>2014-02-28T14:05:54Z</dc:date>
    <item>
      <title>Combine/Merge results from Exim Search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Combine-Merge-results-from-Exim-Search/m-p/169865#M186274</link>
      <description>&lt;P&gt;As first, sry for my bad english.&lt;/P&gt;

&lt;P&gt;At the moment i making a praktical training&lt;BR /&gt;
My ask is to analyze exim4 Logs. My Problem is for example if search for a Message ID, i find 3 results. How can i combine/emerge this three results in one results?&lt;/P&gt;

&lt;P&gt;Thank you.&lt;BR /&gt;
FloFa&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2014 09:36:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Combine-Merge-results-from-Exim-Search/m-p/169865#M186274</guid>
      <dc:creator>FloFa</dc:creator>
      <dc:date>2014-02-28T09:36:44Z</dc:date>
    </item>
    <item>
      <title>Re: Combine/Merge results from Exim Search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Combine-Merge-results-from-Exim-Search/m-p/169866#M186275</link>
      <description>&lt;P&gt;Hi FloFa,&lt;/P&gt;

&lt;P&gt;You have several options, here are two :&lt;BR /&gt;
 - use "stats" function, to group you 3 messages : | stats ... by MessageID&lt;BR /&gt;
 - if you need the raw content from the events, have a look a the "transaction" command : | transaction MessageID |...&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.7/SearchReference/ListOfSearchCommands"&gt;http://docs.splunk.com/Documentation/Splunk/5.0.7/SearchReference/ListOfSearchCommands&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2014 13:39:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Combine-Merge-results-from-Exim-Search/m-p/169866#M186275</guid>
      <dc:creator>sbsbb</dc:creator>
      <dc:date>2014-02-28T13:39:20Z</dc:date>
    </item>
    <item>
      <title>Re: Combine/Merge results from Exim Search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Combine-Merge-results-from-Exim-Search/m-p/169867#M186276</link>
      <description>&lt;P&gt;Could be more specific on what do you mean by merging/combining the results? Probably the output/table you're looking for.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2014 14:05:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Combine-Merge-results-from-Exim-Search/m-p/169867#M186276</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-02-28T14:05:54Z</dc:date>
    </item>
  </channel>
</rss>

