Reporting
Highlighted

How can I put two search results into one report?

Explorer

I want to build a report which can show the result of two fields from different searches?Can splunk do that? Thank u for any advice.

Tags (1)
Highlighted

Re: How can I put two search results into one report?

Splunk Employee
Splunk Employee

Yes. You may use the append command to append results of another search. Here is an unimaginative example of appending the results of a search for one source with the results of a search for another (ignoring the fact that this could be done in one search):

index=_internal source=*metrics| append [search index=_internal source=*access.log] | stats count by source
Highlighted

Re: How can I put two search results into one report?

Explorer

Thank u very much

0 Karma