Webuse the where command to compare two fields.

For not equal comparisons, you can specify the criteria in several ways.

Index=myindex | where fielda=fieldb.

Recommended for you

Some data is in combination of.

Webi have index called index1 which has sourcetype called sourcetype1 and another index called index2 with sourcetype called sourcetype2.

Searching in multiple indexes.

You will need to replace.

If you want to coorelate between both indexes, you can use the search below to get you started.

This command requires at least two subsearches and allows only.

Websep 25, 2019 · splunk search.

If you want to coorelate between both indexes, you can use the search below to get you started.

This command requires at least two subsearches and allows only.

Websep 25, 2019 · splunk search.

Webto search multiple indexes in splunk, use the index and source parameters.

You can use the search command to search multiple indexes at once.

Webthe multisearch command is a generating command that runs multiple streaming searches at the same time.

1) look in a table.

I am trying to create a search to do the following:

Weboct 16, 2012 · you just specify those indexes on the search line:

Keyword=blah index=index1 or index=index2 or index=index3 | foo by bar

Webthe multisearch command is a generating command that runs multiple streaming searches at the same time.

1) look in a table.

I am trying to create a search to do the following:

Weboct 16, 2012 · you just specify those indexes on the search line:

Keyword=blah index=index1 or index=index2 or index=index3 | foo by bar

Keyword=blah index=index1 or index=index2 or index=index3 | foo by bar

You may also like