<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Correlating events from 2 different indexers when there is no common field in Splunk ITSI</title>
    <link>https://community.splunk.com/t5/Splunk-ITSI/Correlating-events-from-2-different-indexers-when-there-is-no/m-p/475621#M1748</link>
    <description>&lt;P&gt;with expected results &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; &lt;/P&gt;</description>
    <pubDate>Tue, 14 Apr 2020 12:18:32 GMT</pubDate>
    <dc:creator>kamlesh_vaghela</dc:creator>
    <dc:date>2020-04-14T12:18:32Z</dc:date>
    <item>
      <title>Correlating events from 2 different indexers when there is no common field</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/Correlating-events-from-2-different-indexers-when-there-is-no/m-p/475619#M1746</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I have 2 different indexers snmptrapd and servicenow.&lt;/P&gt;
&lt;P&gt;Where snmptrap will have NNMI related events for storage devices, such as when any storage device is down/not functional&lt;/P&gt;
&lt;P&gt;and servicenow indexer will have incident related events from CMDB data.&lt;/P&gt;
&lt;P&gt;So i need to get events with storage device down along with respective Incident data.&lt;/P&gt;
&lt;P&gt;Is there any possibility to correlate these 2 indexers, so that i can get required&lt;/P&gt;</description>
      <pubDate>Sun, 07 Jun 2020 00:21:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/Correlating-events-from-2-different-indexers-when-there-is-no/m-p/475619#M1746</guid>
      <dc:creator>vijaya5</dc:creator>
      <dc:date>2020-06-07T00:21:43Z</dc:date>
    </item>
    <item>
      <title>Re: Correlating events from 2 different indexers when there is no common field</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/Correlating-events-from-2-different-indexers-when-there-is-no/m-p/475620#M1747</link>
      <description>&lt;P&gt;@vijaya5 &lt;/P&gt;

&lt;P&gt;Can you provide sample data ?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Apr 2020 10:15:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/Correlating-events-from-2-different-indexers-when-there-is-no/m-p/475620#M1747</guid>
      <dc:creator>harishalipaka</dc:creator>
      <dc:date>2020-04-14T10:15:55Z</dc:date>
    </item>
    <item>
      <title>Re: Correlating events from 2 different indexers when there is no common field</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/Correlating-events-from-2-different-indexers-when-there-is-no/m-p/475621#M1748</link>
      <description>&lt;P&gt;with expected results &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; &lt;/P&gt;</description>
      <pubDate>Tue, 14 Apr 2020 12:18:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/Correlating-events-from-2-different-indexers-when-there-is-no/m-p/475621#M1748</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2020-04-14T12:18:32Z</dc:date>
    </item>
    <item>
      <title>Re: Correlating events from 2 different indexers when there is no common field</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/Correlating-events-from-2-different-indexers-when-there-is-no/m-p/475622#M1749</link>
      <description>&lt;P&gt;I believe "indexers" is mis-used here and should be "indexes".&lt;/P&gt;</description>
      <pubDate>Tue, 14 Apr 2020 12:42:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/Correlating-events-from-2-different-indexers-when-there-is-no/m-p/475622#M1749</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-04-14T12:42:22Z</dc:date>
    </item>
  </channel>
</rss>

