Splunk Search

How to place the results of multiple unrelated searches into a table?

raju4244
Explorer

Dear All,

I have multiple searches with its results. Now I want to put values in a single table and that to be in particular column. Searches don't have any relationship to each other.

Tags (2)
0 Karma
1 Solution

FritzWittwer_ol
Contributor
  • if you want the searches in the same table below each other, you can use the append command
  • if you want to have the results of the searches besides each other ins separate columns, then you could use the join command, but in this case the events need to have some kind of relation

View solution in original post

0 Karma

FritzWittwer_ol
Contributor
  • if you want the searches in the same table below each other, you can use the append command
  • if you want to have the results of the searches besides each other ins separate columns, then you could use the join command, but in this case the events need to have some kind of relation
0 Karma

raju4244
Explorer

Thanks, i used mix of join and append command to make it in single table

0 Karma

raju4244
Explorer

other append or join, do we have any other??

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...

State of Splunk Careers 2024: Maximizing Career Outcomes and the Continued Value of ...

For the past four years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...

Data-Driven Success: Splunk & Financial Services

Splunk streamlines the process of extracting insights from large volumes of data. In this fast-paced world, ...