- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Questions about federated search subsearch?
KwonTaeHoon
Path Finder
02-28-2023
12:24 AM
Hello
I want to ask a question about subsearch.
When submitting a fed command without using it, an error message occurs as follows.
Before setting federated search ]
index=fw | join src_ip [ sourcetype=ips | stats count by src_ip ]
>> Result : OK
After setting federated search ]
index=fw | join src_ip [ sourcetype=ips | stats count by src_ip ]
>> Result : NG
Error : Search command can only accept one federated index.
Is there any solution?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
nejmeddine
Loves-to-Learn
05-04-2023
07:30 AM
can i use federated search between different versions splunk ?
