Hello
I want to ask a question about subsearch.
When submitting a fed command without using it, an error message occurs as follows.
Before setting federated search ]
index=fw | join src_ip [ sourcetype=ips | stats count by src_ip ]
>> Result : OK
After setting federated search ]
index=fw | join src_ip [ sourcetype=ips | stats count by src_ip ]
>> Result : NG
Error : Search command can only accept one federated index.
Is there any solution?
can i use federated search between different versions splunk ?