Dashboards & Visualizations

How to combine my two searches into a single base search and have two different post-process transforming searches?

joydeep741
Path Finder

I have scenario where:

Search 1:

base search | timechart count(field) by X

Search 2:

base search | timechart count(field2) by Y

Can I some how combine these to in a single base search and then have two post processed searches?

0 Karma

gyslainlatsa
Motivator

hi joydeep741,
try like this:

|set union  [base search | timechart count(field) by X]  [base search | timechart count(field2) by Y]
0 Karma

gibba
Path Finder
  • List item base search | timechart count(field) by X | appendcols [ search base search | timechart count(field2) by Y]
0 Karma

joydeep741
Path Finder

But by this approach i will be hitting the Raw data twice. So the purpose of post processing wont be served.

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...