Splunk Search

Extend Search without re-running

thepocketwade
Path Finder

I just ran a search over the last 24 hours which returned a large number of results, but not the full picture I was looking for. So I extended the time frame to the last 7 days. Doing that reran the whole search, including the results I'd already amassed over the last 24 hours.

I could feasibly open a new window and run the search over 6 days, and have the two sets of results to work with; but is there a way to concatenate these results together?

Tags (1)
0 Karma

gkanapathy
Splunk Employee
Splunk Employee

Well, I suppose you could use a combination of the append and loadjob commands.

newsearch | append [ loadjob oldsearchid ]

landen99
Motivator

Found the sid as the last element in the url while the search was loaded/started.

0 Karma

thepocketwade
Path Finder

From the actions menu you can select "Inspect Search." The search inspector window will pop up, and you can find a lot of information (including the search id) there.

0 Karma

christopherutz
Path Finder

This seems very useful. In what methods can the old search id be obtained? I know it can be retrieved from the jobs view but are there any other ways? Does the jobid end up as a field of the results?

0 Karma
Get Updates on the Splunk Community!

AppDynamics Summer Webinars

This summer, our mighty AppDynamics team is cooking up some delicious content on YouTube Live to satiate your ...

SOCin’ it to you at Splunk University

Splunk University is expanding its instructor-led learning portfolio with dedicated Security tracks at .conf25 ...

Credit Card Data Protection & PCI Compliance with Splunk Edge Processor

Organizations handling credit card transactions know that PCI DSS compliance is both critical and complex. The ...