<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic After matching 2 different data sources based on srcip, why is the output none? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/After-matching-2-different-data-sources-based-on-srcip-why-is/m-p/357681#M65321</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I try to match two events in one search. one event must match virus and the other android. because the clearpass name for srcip is Ip_address i use the "|rename".  &lt;/P&gt;

&lt;P&gt;The problem is, the output is none. If I try OR instead of AND, it shows only clearpass output and if I delete the "|rename" it shows only syslog info.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;(index="main" sourcetype="syslog") OR (index="main" sourcetype="aruba:cppm:syslog") |rename ip_address as srcip |transaction srcip keepevicted=true maxspan=-1 |search subtype="virus" AND device_family="android"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Tue, 24 Apr 2018 10:01:45 GMT</pubDate>
    <dc:creator>nielsg97</dc:creator>
    <dc:date>2018-04-24T10:01:45Z</dc:date>
    <item>
      <title>After matching 2 different data sources based on srcip, why is the output none?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/After-matching-2-different-data-sources-based-on-srcip-why-is/m-p/357681#M65321</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I try to match two events in one search. one event must match virus and the other android. because the clearpass name for srcip is Ip_address i use the "|rename".  &lt;/P&gt;

&lt;P&gt;The problem is, the output is none. If I try OR instead of AND, it shows only clearpass output and if I delete the "|rename" it shows only syslog info.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;(index="main" sourcetype="syslog") OR (index="main" sourcetype="aruba:cppm:syslog") |rename ip_address as srcip |transaction srcip keepevicted=true maxspan=-1 |search subtype="virus" AND device_family="android"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 24 Apr 2018 10:01:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/After-matching-2-different-data-sources-based-on-srcip-why-is/m-p/357681#M65321</guid>
      <dc:creator>nielsg97</dc:creator>
      <dc:date>2018-04-24T10:01:45Z</dc:date>
    </item>
  </channel>
</rss>

