Hello,
I have a problem with trying to add a manual event to a query. For example I have a query that produces a list of session ids (SID). I would also like to add another event and this event would only have static information. So given a query that produces the following data:
aa
bb
cc
I want to modify this query to produce this:
Samslara
aa
bb
cc
where "Samslara" is statically declared in the query.
What's the best way to do this?
You could try to use append, something like this
index=someindex | append [ search index=someindex | eval SID="Samslara" | head 1 ] | table SID
http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/append