Splunk Search

Consolidation From Different Sources

Cyber_Nerd3
Engager

Hey Everyone!

I'm in need of some help, advice, Ouija board (lol)...whatever can do the trick. I am wanting to know if it is possible to consolidate data from a search that is not generated on Splunk? My supervisor is wanting to receive 1 report instead of 2. Do any of you know if this is even possible? 

Thanks,

Cyber_Nerd3

0 Karma

Cyber_Nerd3
Engager

Ok @ITWhisperer  & @richgalloway  I just got clarification on everything and what he wants is to combine multiple reports located within Splunk into 1 report. I apologize for the misunderstanding on my part, but if either of you could give any input on how to achieve this it would be greatly appreciated.

Thank you!

0 Karma

richgalloway
SplunkTrust
SplunkTrust

We need to know more about the two reports.  How similar are they?  What searches do they use? 

In principle, two reports can be combined, but exactly to do that depends heavily on the reports themselves.  There is no generic answer.

---
If this reply helps you, Karma would be appreciated.
0 Karma

Cyber_Nerd3
Engager

4 are firewall logs which need to be combined into 1 report and the other 2 are just Windows reports. 

I hope this helps, 

Thanks

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Yeah, not really, other than to confirm my "maybe" response.

Search these forums (Google works well) for "combine searches" and you should get a lot of good examples both of how to ask this question and how to solve it.

---
If this reply helps you, Karma would be appreciated.
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Ingest the data or report from the other search into splunk and produce one report from splunk (or tell you supervisor to "man up" and deal with two reports! lol 😀)

Tags (2)

Cyber_Nerd3
Engager

Lol, Thank you so much!

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Please tell us more about the use case.  Where is the other data generated?  Is this other source integrated with Splunk?

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...