<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Join query with common fields from different logs in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Join-query-with-common-fields-from-different-logs/m-p/504293#M140769</link>
    <description>&lt;P&gt;index=yours source=AAA OR source=BBB&lt;BR /&gt;| fields&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;A1&amp;nbsp; A2&amp;nbsp; B3&amp;nbsp; B4&lt;BR /&gt;| stats values(*) as *&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I don't have any details at all, so that's about it.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 14 Jun 2020 02:24:01 GMT</pubDate>
    <dc:creator>to4kawa</dc:creator>
    <dc:date>2020-06-14T02:24:01Z</dc:date>
    <item>
      <title>Join query with common fields from different logs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Join-query-with-common-fields-from-different-logs/m-p/504061#M140719</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;I need to find common fields from two different logs. After finding common fields I need to extract the result as a table. I need help with the first part of my problem. I have two different log files with the names of AAA and BBB. How can I compare them and find the common fields?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jun 2020 06:19:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Join-query-with-common-fields-from-different-logs/m-p/504061#M140719</guid>
      <dc:creator>alico</dc:creator>
      <dc:date>2020-06-12T06:19:58Z</dc:date>
    </item>
    <item>
      <title>Re: Join query with common fields from different logs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Join-query-with-common-fields-from-different-logs/m-p/504093#M140727</link>
      <description>&lt;P&gt;Documentation relating to the join command can be found here:&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.4/SearchReference/Join" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.4/SearchReference/Join&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;for further assistance here, we really need to see a snapshot of the logs and what you're trying to do. It may be that there's also an answer within this site already so please check there&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jun 2020 08:56:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Join-query-with-common-fields-from-different-logs/m-p/504093#M140727</guid>
      <dc:creator>twesty</dc:creator>
      <dc:date>2020-06-12T08:56:08Z</dc:date>
    </item>
    <item>
      <title>Re: Join query with common fields from different logs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Join-query-with-common-fields-from-different-logs/m-p/504238#M140758</link>
      <description>&lt;P&gt;Thank you for your reply,&lt;/P&gt;&lt;P&gt;I already did research from documents but because of my lack of knowledge I couldn't resolve it. Let me change the question then and, be more specific about my question. I have two log files AAA and BBB. I want to add some fields from these logs, lets say A1 and A2 fields from AAA and B3 and B4 fields from BBB. They are not identical, I just want to add those fields and extract the output as a table. How can I do that?&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jun 2020 19:45:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Join-query-with-common-fields-from-different-logs/m-p/504238#M140758</guid>
      <dc:creator>alico</dc:creator>
      <dc:date>2020-06-12T19:45:44Z</dc:date>
    </item>
    <item>
      <title>Re: Join query with common fields from different logs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Join-query-with-common-fields-from-different-logs/m-p/504293#M140769</link>
      <description>&lt;P&gt;index=yours source=AAA OR source=BBB&lt;BR /&gt;| fields&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;A1&amp;nbsp; A2&amp;nbsp; B3&amp;nbsp; B4&lt;BR /&gt;| stats values(*) as *&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I don't have any details at all, so that's about it.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 14 Jun 2020 02:24:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Join-query-with-common-fields-from-different-logs/m-p/504293#M140769</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-06-14T02:24:01Z</dc:date>
    </item>
  </channel>
</rss>

