How can I put two search results into one report?


I want to build a report which can show the result of two fields from different searches?Can splunk do that? Thank u for any advice.

Tags (1)

Splunk Employee
Splunk Employee

Yes. You may use the append command to append results of another search. Here is an unimaginative example of appending the results of a search for one source with the results of a search for another (ignoring the fact that this could be done in one search):

index=_internal source=*metrics| append [search index=_internal source=*access.log] | stats count by source


Thank u very much

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!