Splunk Search

How to combine two searches?

alexrod03
New Member

I need to look for an incoming email and if an email matches a certain subject, I need to check another source type to see if within an hour of that email coming through there was a hit on that sourcetype. 

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

What do you have so far?  Do you have the two searches you want to combine?

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Wrapping Up Cybersecurity Awareness Month

October might be wrapping up, but for Splunk Education, cybersecurity awareness never goes out of season. ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...

What's New in Splunk Observability - October 2025

What’s New?    We’re excited to announce the latest enhancements to Splunk Observability Cloud and share ...