Splunk® Cloud Services

SPL2 Search Reference

Acrobat logo Download manual as PDF

Acrobat logo Download topic as PDF

union command overview

Merges the results from two or more datasets into one larger dataset. One of the datasets can be the incoming search results that are then piped into the union command and merged with a second dataset.

If all of the datasets that you want to merge are indexes, you can use the indexes dataset function instead of the union command. See indexes dataset function.


The required syntax is in bold.

<dataset> ["," <dataset>...]

See also

union command
union command syntax details
union command usage
union command examples
Last modified on 14 July, 2021
timewrap command examples
union command syntax details

This documentation applies to the following versions of Splunk® Cloud Services: current

Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters