How can I put two search results into one report?


I want to build a report which can show the result of two fields from different searches?Can splunk do that? Thank u for any advice.

Yes. You may use the append command to append results of another search. Here is an unimaginative example of appending the results of a search for one source with the results of a search for another (ignoring the fact that this could be done in one search):

index=_internal source=*metrics| append [search index=_internal source=*access.log] | stats count by source


Thank u very much

