is it possible to merge two or more event results in one? The events are from the same field.
Reason : I have a dashboard which can just show one result and it doens't recognize the other fields, just one. So I thought I merge all events in one line in a row.
How can I do this?
Have you looked into transaction (http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/transaction)?
Does the mvcombine command do what you want ?
View solution in original post