<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Consolidation From Different Sources in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Consolidation-From-Different-Sources/m-p/564448#M196631</link>
    <description>&lt;P&gt;Yeah, not really, other than to confirm my "maybe" response.&lt;/P&gt;&lt;P&gt;Search these forums (Google works well) for "combine searches" and you should get a lot of good examples both of how to ask this question and how to solve it.&lt;/P&gt;</description>
    <pubDate>Tue, 24 Aug 2021 00:01:59 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2021-08-24T00:01:59Z</dc:date>
    <item>
      <title>Consolidation From Different Sources</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Consolidation-From-Different-Sources/m-p/564346#M196596</link>
      <description>&lt;P&gt;Hey Everyone!&lt;/P&gt;&lt;P&gt;I'm in need of some help, advice, Ouija board (lol)...whatever can do the trick. I am wanting to know if it is possible to consolidate data from a search that is not generated on Splunk? My supervisor is wanting to receive 1 report instead of 2. Do any of you know if this is even possible?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Cyber_Nerd3&lt;/P&gt;</description>
      <pubDate>Mon, 23 Aug 2021 14:02:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Consolidation-From-Different-Sources/m-p/564346#M196596</guid>
      <dc:creator>Cyber_Nerd3</dc:creator>
      <dc:date>2021-08-23T14:02:43Z</dc:date>
    </item>
    <item>
      <title>Re: Consolidation From Different Sources</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Consolidation-From-Different-Sources/m-p/564350#M196599</link>
      <description>&lt;P&gt;Please tell us more about the use case.&amp;nbsp; Where is the other data generated?&amp;nbsp; Is this other source integrated with Splunk?&lt;/P&gt;</description>
      <pubDate>Mon, 23 Aug 2021 14:23:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Consolidation-From-Different-Sources/m-p/564350#M196599</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-08-23T14:23:02Z</dc:date>
    </item>
    <item>
      <title>Re: Consolidation From Different Sources</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Consolidation-From-Different-Sources/m-p/564352#M196601</link>
      <description>&lt;P&gt;Ingest the data or report from the other search into splunk and produce one report from splunk (or tell you supervisor to "man up" and deal with two reports! lol &lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt;)&lt;/P&gt;</description>
      <pubDate>Mon, 23 Aug 2021 14:24:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Consolidation-From-Different-Sources/m-p/564352#M196601</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-08-23T14:24:08Z</dc:date>
    </item>
    <item>
      <title>Re: Consolidation From Different Sources</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Consolidation-From-Different-Sources/m-p/564377#M196609</link>
      <description>&lt;P&gt;Lol, Thank you so much!&lt;/P&gt;</description>
      <pubDate>Mon, 23 Aug 2021 15:28:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Consolidation-From-Different-Sources/m-p/564377#M196609</guid>
      <dc:creator>Cyber_Nerd3</dc:creator>
      <dc:date>2021-08-23T15:28:26Z</dc:date>
    </item>
    <item>
      <title>Re: Consolidation From Different Sources</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Consolidation-From-Different-Sources/m-p/564393#M196612</link>
      <description>&lt;P&gt;Ok&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp; &amp;amp;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp; I just got clarification on everything and what he wants is to combine multiple reports located within Splunk into 1 report. I apologize for the misunderstanding on my part, but if either of you could give any input on how to achieve this it would be greatly appreciated.&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Mon, 23 Aug 2021 16:35:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Consolidation-From-Different-Sources/m-p/564393#M196612</guid>
      <dc:creator>Cyber_Nerd3</dc:creator>
      <dc:date>2021-08-23T16:35:19Z</dc:date>
    </item>
    <item>
      <title>Re: Consolidation From Different Sources</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Consolidation-From-Different-Sources/m-p/564395#M196613</link>
      <description>&lt;P&gt;We need to know more about the two reports.&amp;nbsp; How similar are they?&amp;nbsp; What searches do they use?&amp;nbsp;&lt;/P&gt;&lt;P&gt;In principle, two reports can be combined, but exactly to do that depends heavily on the reports themselves.&amp;nbsp; There is no generic answer.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Aug 2021 16:39:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Consolidation-From-Different-Sources/m-p/564395#M196613</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-08-23T16:39:53Z</dc:date>
    </item>
    <item>
      <title>Re: Consolidation From Different Sources</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Consolidation-From-Different-Sources/m-p/564396#M196614</link>
      <description>&lt;P&gt;4 are firewall logs which need to be combined into 1 report and the other 2 are just Windows reports.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 23 Aug 2021 16:55:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Consolidation-From-Different-Sources/m-p/564396#M196614</guid>
      <dc:creator>Cyber_Nerd3</dc:creator>
      <dc:date>2021-08-23T16:55:29Z</dc:date>
    </item>
    <item>
      <title>Re: Consolidation From Different Sources</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Consolidation-From-Different-Sources/m-p/564448#M196631</link>
      <description>&lt;P&gt;Yeah, not really, other than to confirm my "maybe" response.&lt;/P&gt;&lt;P&gt;Search these forums (Google works well) for "combine searches" and you should get a lot of good examples both of how to ask this question and how to solve it.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Aug 2021 00:01:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Consolidation-From-Different-Sources/m-p/564448#M196631</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-08-24T00:01:59Z</dc:date>
    </item>
  </channel>
</rss>

