Splunk Search

How to fetch data from multiple source types in a dashboard ?

rijinc
Explorer

Hi Team,

I have three sourcetypes, all the sourcetypes have two or three common fields , how to extract the data as it should fetch data from all three source type
for ex: Field "City" is common in all source types, to display it on a dashboard using dropdown, what will be the search query or suggest some way to start on this

My idea is to execute search string : input lookup file1.csv file2.csv file3.csv|stats city as City is this correct ?
or is there any convenient way to fetch it easily

Tags (1)
0 Karma

cmerriman
Super Champion

if they are lookup files, maybe something like this:

|inputlookup file1.csv|table City|append [|inputlookup file2.csv|table City]|append [|inputlookup file3.csv|table City]|stats count by City|fields - count
0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...