Splunk version 4.3
search A : index=webserver1 type=error | table serverName message method search B : index=webserver2 type=error | table serverName message method search C : index=webserver1 type=error | table serverName message method | APPEND [index=webserver2 type=error] | table serverName message method
search A results is 20. search B results is 0. search C results is 0. Why?
I expected results is 20+0=20.
Thanks. Everyone