Weboct 16, 2012 · you just specify those indexes on the search line:

Webfeb 20, 2019 · yes correct, this will search both indexes.

Websep 25, 2019 · splunk search.

Recommended for you

Webto search multiple indexes in splunk, use the index and source parameters.

Some data is in combination of.

Keyword=blah index=index1 or index=index2 or index=index3 | foo by bar

1) look in a table.

You can use the search command to search multiple indexes at once.

Webthe multisearch command is a generating command that runs multiple streaming searches at the same time.

Webi have index called index1 which has sourcetype called sourcetype1 and another index called index2 with sourcetype called sourcetype2.

You can use the search command to search multiple indexes at once.

Webthe multisearch command is a generating command that runs multiple streaming searches at the same time.

Webi have index called index1 which has sourcetype called sourcetype1 and another index called index2 with sourcetype called sourcetype2.

Searching in multiple indexes.

If you want to coorelate between both indexes, you can use the search below to get you started.

This command requires at least two subsearches and allows only.

Webuse the where command to compare two fields.

You will need to replace.

Index=myindex | where fielda=fieldb.

I am trying to create a search to do the following:

🔗 Related Articles You Might Like:

This command requires at least two subsearches and allows only.

Webuse the where command to compare two fields.

You will need to replace.

Index=myindex | where fielda=fieldb.

I am trying to create a search to do the following:

I am trying to create a search to do the following:

You may also like