Splunk Search

How to place the results of multiple unrelated searches into a table?

raju4244
Explorer

Dear All,

I have multiple searches with its results. Now I want to put values in a single table and that to be in particular column. Searches don't have any relationship to each other.

Tags (2)
0 Karma
1 Solution

FritzWittwer_ol
Contributor
  • if you want the searches in the same table below each other, you can use the append command
  • if you want to have the results of the searches besides each other ins separate columns, then you could use the join command, but in this case the events need to have some kind of relation

View solution in original post

0 Karma

FritzWittwer_ol
Contributor
  • if you want the searches in the same table below each other, you can use the append command
  • if you want to have the results of the searches besides each other ins separate columns, then you could use the join command, but in this case the events need to have some kind of relation
0 Karma

raju4244
Explorer

Thanks, i used mix of join and append command to make it in single table

0 Karma

raju4244
Explorer

other append or join, do we have any other??

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...