<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Step By Step Searches in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Step-By-Step-Searches/m-p/169909#M48581</link>
    <description>&lt;P&gt;Agreed, much better than append if the searches lend themselves to it.&lt;/P&gt;</description>
    <pubDate>Fri, 28 Feb 2014 13:14:57 GMT</pubDate>
    <dc:creator>wpreston</dc:creator>
    <dc:date>2014-02-28T13:14:57Z</dc:date>
    <item>
      <title>Step By Step Searches</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Step-By-Step-Searches/m-p/169906#M48578</link>
      <description>&lt;P&gt;Hi&lt;BR /&gt;
If I feel difficult to achieve the search result in  a single search,is there any way to do it in multiple steps like plsql procedures?&lt;BR /&gt;
I mean i have 2 search result from 2 different sources and i want to merge the result is there any way?&lt;BR /&gt;
i tried to join data but it will not solve my requirements.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2014 12:21:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Step-By-Step-Searches/m-p/169906#M48578</guid>
      <dc:creator>jimjohn</dc:creator>
      <dc:date>2014-02-28T12:21:59Z</dc:date>
    </item>
    <item>
      <title>Re: Step By Step Searches</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Step-By-Step-Searches/m-p/169907#M48579</link>
      <description>&lt;P&gt;How about the &lt;STRONG&gt;append&lt;/STRONG&gt; command?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... search 1 | append [search search 2 ...]
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 28 Feb 2014 12:31:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Step-By-Step-Searches/m-p/169907#M48579</guid>
      <dc:creator>wpreston</dc:creator>
      <dc:date>2014-02-28T12:31:53Z</dc:date>
    </item>
    <item>
      <title>Re: Step By Step Searches</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Step-By-Step-Searches/m-p/169908#M48580</link>
      <description>&lt;P&gt;or use the two sources in the base search&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;source=1 OR source=2 searchstring1 OR searchstring2&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2014 12:45:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Step-By-Step-Searches/m-p/169908#M48580</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-02-28T12:45:14Z</dc:date>
    </item>
    <item>
      <title>Re: Step By Step Searches</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Step-By-Step-Searches/m-p/169909#M48581</link>
      <description>&lt;P&gt;Agreed, much better than append if the searches lend themselves to it.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2014 13:14:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Step-By-Step-Searches/m-p/169909#M48581</guid>
      <dc:creator>wpreston</dc:creator>
      <dc:date>2014-02-28T13:14:57Z</dc:date>
    </item>
    <item>
      <title>Re: Step By Step Searches</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Step-By-Step-Searches/m-p/169910#M48582</link>
      <description>&lt;P&gt;Ok fine.But In my requirement I doesn't have specific input sting.I need to group column data using transaction.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2014 13:25:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Step-By-Step-Searches/m-p/169910#M48582</guid>
      <dc:creator>jimjohn</dc:creator>
      <dc:date>2014-02-28T13:25:02Z</dc:date>
    </item>
    <item>
      <title>Re: Step By Step Searches</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Step-By-Step-Searches/m-p/169911#M48583</link>
      <description>&lt;P&gt;It would be better if can share the two searches, you're using currently and the requirement for combined search.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2014 14:08:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Step-By-Step-Searches/m-p/169911#M48583</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-02-28T14:08:37Z</dc:date>
    </item>
    <item>
      <title>Re: Step By Step Searches</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Step-By-Step-Searches/m-p/169912#M48584</link>
      <description>&lt;P&gt;Without knowing more about your data or your requirements, like somesoni2 said, it is difficult to help.  I'm guessing that you need to use &lt;STRONG&gt;transaction&lt;/STRONG&gt; in both searches?  If so, you could use &lt;STRONG&gt;transaction&lt;/STRONG&gt; on either side of &lt;STRONG&gt;append&lt;/STRONG&gt;, like so:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... your search 1 
| transaction &amp;lt;transaction options&amp;gt; 
| append [search your search 2 
    | transaction &amp;lt;options&amp;gt;]
| your report command
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Or if you need to make a single transaction out of results from both searches you could try:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;source=1 OR source=2 search1 OR search 2
| transaction &amp;lt;options&amp;gt;
| report command
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 28 Feb 2014 14:40:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Step-By-Step-Searches/m-p/169912#M48584</guid>
      <dc:creator>wpreston</dc:creator>
      <dc:date>2014-02-28T14:40:26Z</dc:date>
    </item>
  </channel>
</rss>

