Use loadjob. Once the first search completes, use the Job Inspector to get the SID. Then replace the original search with a loadjob command and add the new commands. | loadjob 1619199687.119898 | search host=bar Note: the ability to do this without the loadjob kludge is an old ask. Go to https://ideas.splunk.com to add your voice.
... View more