Could be more specific on what do you mean by merging/combining the results? Probably the output/table you're looking for.
Hi FloFa,
You have several options, here are two :
- use "stats" function, to group you 3 messages : | stats ... by MessageID
- if you need the raw content from the events, have a look a the "transaction" command : | transaction MessageID |...
http://docs.splunk.com/Documentation/Splunk/5.0.7/SearchReference/ListOfSearchCommands