<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic search same requestid from different sources and fileds in Splunk Dev</title>
    <link>https://community.splunk.com/t5/Splunk-Dev/search-same-requestid-from-different-sources-and-fileds/m-p/421332#M7388</link>
    <description>&lt;P&gt;I don;t know what's eval command I need to here but I like to make SPL like before&lt;/P&gt;

&lt;P&gt;sourcetype A , field_a(requestid) field_a2 , field_a3 ,field_a4&lt;/P&gt;

&lt;P&gt;sourcetype B, field_b(requestid) field_b2, field_b3, filed_b4&lt;/P&gt;

&lt;P&gt;(what kind of eval or join i need to use here ) ?????&lt;/P&gt;

&lt;P&gt;where field_a(requestid)=field_b(requestid)&lt;/P&gt;

&lt;P&gt;table field_a(requestid) field_b(requestid) field_a3 ,field_a4 ,filed_b4 &lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 19:42:32 GMT</pubDate>
    <dc:creator>diag</dc:creator>
    <dc:date>2020-09-29T19:42:32Z</dc:date>
    <item>
      <title>search same requestid from different sources and fileds</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/search-same-requestid-from-different-sources-and-fileds/m-p/421332#M7388</link>
      <description>&lt;P&gt;I don;t know what's eval command I need to here but I like to make SPL like before&lt;/P&gt;

&lt;P&gt;sourcetype A , field_a(requestid) field_a2 , field_a3 ,field_a4&lt;/P&gt;

&lt;P&gt;sourcetype B, field_b(requestid) field_b2, field_b3, filed_b4&lt;/P&gt;

&lt;P&gt;(what kind of eval or join i need to use here ) ?????&lt;/P&gt;

&lt;P&gt;where field_a(requestid)=field_b(requestid)&lt;/P&gt;

&lt;P&gt;table field_a(requestid) field_b(requestid) field_a3 ,field_a4 ,filed_b4 &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:42:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/search-same-requestid-from-different-sources-and-fileds/m-p/421332#M7388</guid>
      <dc:creator>diag</dc:creator>
      <dc:date>2020-09-29T19:42:32Z</dc:date>
    </item>
    <item>
      <title>Re: search same requestid from different sources and fileds</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/search-same-requestid-from-different-sources-and-fileds/m-p/421333#M7389</link>
      <description>&lt;P&gt;Try this!&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;(sourcetype=sourcetype A OR  sourcetype=sourcetype B)
|eval key=if(sourcetype=sourcetype A, field_a, field_b)
|stats earliest(*) as * by key
|table field_a,field_b,field_a3 ,field_a4 ,filed_b4 
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 28 May 2018 11:44:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/search-same-requestid-from-different-sources-and-fileds/m-p/421333#M7389</guid>
      <dc:creator>HiroshiSatoh</dc:creator>
      <dc:date>2018-05-28T11:44:30Z</dc:date>
    </item>
    <item>
      <title>Re: search same requestid from different sources and fileds</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/search-same-requestid-from-different-sources-and-fileds/m-p/421334#M7390</link>
      <description>&lt;P&gt;Hi @diag ,&lt;/P&gt;

&lt;P&gt;Can you please try following search?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;(sourcetype=A OR sourcetype=B) (field_a=* OR field_b=*)
| eval requestid=if(isnotnull(field_a),field_a,field_b) 
| stats latest(field_a) as field_a latest(field_b) as field_b latest(field_a3) as field_a3, latest(field_a4) as field_a4,latest(field_b4) as field_b4 by requestid 
| where field_a = field_b
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This is my sample search&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| makeresults 
| eval sourcetype="A",field_a="1,2,3,4",field_a2="a2",field_a3="a3", field_a4="a4" 
| eval field_a=split(field_a,",") 
| mvexpand field_a 
| append 
    [| makeresults 
    | eval sourcetype="B",field_b="1,2,3",field_b2="b2",field_b3="b3", field_b4="b4" 
    | eval field_b=split(field_b,",") 
    | mvexpand field_b] 
| eval comment="Above search is for data generation. Use from below search"
| search (sourcetype=A OR sourcetype=B) (field_a=* OR field_b=*)
| eval requestid=if(isnotnull(field_a),field_a,field_b) 
| stats latest(field_a) as field_a latest(field_b) as field_b latest(field_a3) as field_a3, latest(field_a4) as field_a4,latest(field_b4) as field_b4 by requestid 
| where field_a = field_b
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 28 May 2018 11:54:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/search-same-requestid-from-different-sources-and-fileds/m-p/421334#M7390</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2018-05-28T11:54:41Z</dc:date>
    </item>
  </channel>
</rss>

