Hi,
I am trying to run a search query wherein where in output of one query acts as inupt for the following query.
Please help me with the syntax.
Also,please let me know how can i view the second query resul in dashbaord. (Means when i click on visualization i should be redirected towards the second query dashboard.
Please help.
Thanks & Regards,
Nidhi Gupta
..I am trying to run a search query wherein where in output of one query acts as inupt for the following query
While using pipes |
, by default, first query output will be passed to second query. for example,
index=app search-for-something | table source, sourcetype, _time
..how can i view the second query result in dashboard
You can use timechart command, or chart commands, which will create the visualizations
http://docs.splunk.com/Documentation/Splunk/6.4.3/SearchReference/Timechart
Can you provide us more info about the requirement, so that we can suggest you exactly how to proceed?
Hello,
Basically I am querying one of the sourcetype and its field is to be matched with the second sourcetype and I want to show fields from second sourcetype after matching data from the 1st sourcetype .
In the database sense I want to use join between two sourcetype .
Thanks,
Nidhi
Hi Nidhi,
Maybe, like this.. there is a join command in Splunk as well, but that may not be needed for this one, I think.
search index=app sourcetype=abc | table host
This will search for sourcetype abc on index app, and returns the list of host names.
This search below will check on index app, for sourcetype a1b1c1, and only for the host list from first search.
index=app sourcetype=a1b1c1 [search index=app sourcetype=abc | table host] | table _raw _time
if you update us with your present search or more info on the requirement, we can suggest exactly.
Could you be more specific? What are the two queries?