Splunk Search

data acceleration model


I have a accelerated data model where I would like to run multiple searches. Total of four searches running to find data going back four weeks ( eval _time = -7d@d, eval _time = -14d@d , ect)  

Is there a way to run a multisearch using tstats that would run through by accelerated data model or is there a way to do this over the pivot table?


Please let me know if I need to provide more context.

Labels (1)
0 Karma


Is there a specific reason you need to execute multiple searches concurrently rather than provide an appropriately broad where clause?

0 Karma