Hi Guys, I'm trying to create a table with the count emails sent and emails received from a given emails addresses Column 1 Column 2 Column 3 Email addresses Emails received email sent bob1@splunk.com <Number> <Number> bob2@splunk.com <Number> <Number> I tried this with append command but the result are shown under one another my search is index=email_index Recipients IN(bob1@splunk.com, bob2@splunk.com, bob3@splunk.com ) |stats count as "Emails received" by Recipients | append [search index=email_index Sender IN(bob1@splunk.com, bob2@splunk.com, bob3@splunk.com ) |stats count as "Emails sent" by Sender] |table "Emails received" "Emails sent" Recipients Sender Anyone can help me please?
... View more