Hi all,
i have an doubt please clarify me ..
in the search panel ..is it possible to give two source and get the output
thanks
Yes you can splunkpoornima e.g. sourcetype="HiqLogEndPoints" OR sourcetype="HiqLogAlert"
It may be more elegant to create an eventtype
Br
D
I don't see why this isn't possible...as in all things some are a little more difficult 😉
If you try a search using both sources | eval something-you-want-to-trend-optionally | timechart min(field) or whatever your criteria is...then I figure all that remains is to identify the difference...similar to using a tag between the field from choice A (Dec-4-2012) and choice B (DEC-5-2012). Is that what you are trying to achieve?
THANKS..
but i created two dropdown in which ..in first dropdown i seleted the one taskmanager file of the day Dec-4-2012..in anothere dropdown i selected the another Taskmanager file of the day DEC-5-2012..
so i need is after i selected the two file i want timechart shows the trend for two log files..in one timechart
is it possible ????