how to combine 3 searchs in one alert result ?

New Member

Hello All,

Could you please let me know how to combine 3 searches in one alert ?

like i have 3 indexes
index =a|table test |append [search index=b|table test]|append [search index=c|table test ]

0 Karma


I am not clear that what you want to achieve. Can you try below query and let me know if this is what you expected:

index =a OR index=b OR index=c |dedup test|table test

0 Karma


What is your alert condition

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...

Edge Processor Scaling, Energy & Manufacturing Use Cases, and More New Articles on ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Get More Out of Your Security Practice With a SIEM

Get More Out of Your Security Practice With a SIEMWednesday, July 31, 2024  |  11AM PT / 2PM ETREGISTER ...