...o get it working yet...
| union
[search index=xmo2-aws host=xmo2-prod* sourcetype=oss_app_log "Step completion_code set/reset" (flow_name=UcdeDeviceOnboarding AND step_name=S...
I'm trying to UNION two different tables containing info on foreign traffic - the first table is a log with time range earliest=-24h latest=-1h. The second are logs of those same systems for the f...
...earch criteria common except sorting by column
I want to union of two in one query and extract even duplicate result, what will be that one query please?
When comparing multivalue fields, there are a number of relationships one might be interested in. Equality is easy to check, but what about more complex relationships? Are any members of f1 i...
I have a query that produces results that has two columns :
| field1 | field2 |
Field1 & Field2 have same domain, i.e. takes same set of values. I need to find out Union of the d...
Hi - I'm trying to union/intersect results from different source type using the SET command:
set union [search sourcetype="first_source" 404 | fields url] [search sourcetype="second_source" 3...
Hi Splunk Experts--
I'm confused about the union command and am hoping you can
help. Specifically, I'm struggling to understand what causes the
"things that get unioned" to be truncated-- in m...
Hello
I'm running this query:
| union
[ search host="puppet-01" OR host="jenkins-01" OR host="ANSIBLE-01" sourcetype=ProductionDeploy NOT Permisson_Job_Name=*_permission E...
i All
There are query splunk like this :
(index=Prod sourcetype=ProdApp (host=Prod01 OR Prod02) source="/prodlib/SPLID" "Response" ERR-12120)
| rex "^(?:[^\[\n]*\[){6}(?P<...
...o see all above counters in one query in either bars or graphs so for that I am making my query like given below but it is not working. Kindly suggest where I am doing wrong?
|set union [search i...