Hi I have 10 different Splunk queries that return results only when there is an issue or a flag of 1. All the queries return the same fields time, message,flag.
can the results of these 10 Splunk queries be made into a table or a report ? So when ever a new issue comes this table is to be updated ?
You can use the append
command, especially since they all have the same fields:
search1
| append [search2]
| append [search3]
Note that the subsearches are limited to 10k each when used with append
.