Hey Everyone!
I'm in need of some help, advice, Ouija board (lol)...whatever can do the trick. I am wanting to know if it is possible to consolidate data from a search that is not generated on Splunk? My supervisor is wanting to receive 1 report instead of 2. Do any of you know if this is even possible?
Thanks,
Cyber_Nerd3
Ok @ITWhisperer & @richgalloway I just got clarification on everything and what he wants is to combine multiple reports located within Splunk into 1 report. I apologize for the misunderstanding on my part, but if either of you could give any input on how to achieve this it would be greatly appreciated.
Thank you!
We need to know more about the two reports. How similar are they? What searches do they use?
In principle, two reports can be combined, but exactly to do that depends heavily on the reports themselves. There is no generic answer.
4 are firewall logs which need to be combined into 1 report and the other 2 are just Windows reports.
I hope this helps,
Thanks
Yeah, not really, other than to confirm my "maybe" response.
Search these forums (Google works well) for "combine searches" and you should get a lot of good examples both of how to ask this question and how to solve it.
Lol, Thank you so much!
Please tell us more about the use case. Where is the other data generated? Is this other source integrated with Splunk?