Splunk Search

How to combine multiple independent search results in a single table row with multiple columns?

722624
Path Finder
  1. I have 5 different searches (each search itself contains commands join, multisearch etc...),
  2. From each search, I get 3 to 4 fields,
  3. I have to show these fields in a single row of a table in multiple columns (so table the contains columns 15-20)

Could you please help if this is possible?

Thank you
AB

0 Karma

jagadeeshm
Contributor

What you are probably looking for is an appendcol command.

You can try something like this -

your_search_query_1|appendcols [search your_search_query_2]

Reference # http://docs.splunk.com/Documentation/Splunk/6.5.0/SearchReference/Appendcols

0 Karma