oh great thanks, that is definetly in the direction I wanna go.
But how can I fill the different Severnames with data from a Splunk query. The example above was just to Show what I wanna do or see.
At the end of the day, I wanna have a query which fills Server A and Server B and so on with data out of my Indexes.
I am really new to splunk maybe my question is stupid but can I do something like:
..... | eval Users-CPU=case((Servername="Server A"), "[query1]::[query2]",
(Servername="Server B"), "[query3]::[query4]",
(Servername="Server C"), "[query3]::[query4]")......|.....
and of course the quer* will return several rows of data.....
... View more