<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Using three events without common fields to get list of IDs in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Using-three-events-without-common-fields-to-get-list-of-IDs/m-p/520900#M146736</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I'm trying to figure out how to get my hands on a list of IDs which are determined by referring to three events. I have to&amp;nbsp;&lt;EM&gt;not&lt;/EM&gt; use things such as&amp;nbsp;&lt;STRONG&gt;join&lt;/STRONG&gt;, &lt;STRONG&gt;transaction&lt;/STRONG&gt;, or &lt;STRONG&gt;sub-search&lt;/STRONG&gt; due to the event limits involved.&lt;/P&gt;&lt;P&gt;Specifically, I have:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;STRONG&gt;Event A&lt;/STRONG&gt; which contains a &lt;STRONG&gt;req_id&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Event B&lt;/STRONG&gt; which contains the same&amp;nbsp;&lt;STRONG&gt;req_id&lt;/STRONG&gt; and a&amp;nbsp;&lt;STRONG&gt;correlationId&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Event C&lt;/STRONG&gt; which does &lt;EM&gt;not&lt;/EM&gt; contain a &lt;STRONG&gt;req_id&lt;/STRONG&gt; but contains the&amp;nbsp;&lt;STRONG&gt;correlationId&amp;nbsp;&lt;/STRONG&gt;from&lt;STRONG&gt; Event B&amp;nbsp;&lt;/STRONG&gt;and also a &lt;STRONG&gt;personId&lt;/STRONG&gt; that I need&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;The reason I need to use&amp;nbsp;&lt;STRONG&gt;Event A&lt;/STRONG&gt; rather than just look at &lt;STRONG&gt;Event B&lt;/STRONG&gt; and &lt;STRONG&gt;Event C&lt;/STRONG&gt; is because there are numerous occurrences of&amp;nbsp;&lt;STRONG&gt;Event B&lt;/STRONG&gt;&amp;nbsp;that are unrelated, so I first have to ensure they can be associated with an &lt;STRONG&gt;Event A&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;TLDR! I need the list of&amp;nbsp;&lt;STRONG&gt;personId&lt;/STRONG&gt; values that come from&amp;nbsp;&lt;STRONG&gt;Event C&lt;/STRONG&gt;, but first I need to make sure they are associated with&amp;nbsp;&lt;STRONG&gt;Event A&lt;/STRONG&gt; and&amp;nbsp;&lt;STRONG&gt;Event B &lt;/STRONG&gt;— the challenge being there is no one value contained by all three.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 22 Sep 2020 17:27:36 GMT</pubDate>
    <dc:creator>RyanJWilliams</dc:creator>
    <dc:date>2020-09-22T17:27:36Z</dc:date>
    <item>
      <title>Using three events without common fields to get list of IDs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Using-three-events-without-common-fields-to-get-list-of-IDs/m-p/520900#M146736</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I'm trying to figure out how to get my hands on a list of IDs which are determined by referring to three events. I have to&amp;nbsp;&lt;EM&gt;not&lt;/EM&gt; use things such as&amp;nbsp;&lt;STRONG&gt;join&lt;/STRONG&gt;, &lt;STRONG&gt;transaction&lt;/STRONG&gt;, or &lt;STRONG&gt;sub-search&lt;/STRONG&gt; due to the event limits involved.&lt;/P&gt;&lt;P&gt;Specifically, I have:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;STRONG&gt;Event A&lt;/STRONG&gt; which contains a &lt;STRONG&gt;req_id&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Event B&lt;/STRONG&gt; which contains the same&amp;nbsp;&lt;STRONG&gt;req_id&lt;/STRONG&gt; and a&amp;nbsp;&lt;STRONG&gt;correlationId&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Event C&lt;/STRONG&gt; which does &lt;EM&gt;not&lt;/EM&gt; contain a &lt;STRONG&gt;req_id&lt;/STRONG&gt; but contains the&amp;nbsp;&lt;STRONG&gt;correlationId&amp;nbsp;&lt;/STRONG&gt;from&lt;STRONG&gt; Event B&amp;nbsp;&lt;/STRONG&gt;and also a &lt;STRONG&gt;personId&lt;/STRONG&gt; that I need&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;The reason I need to use&amp;nbsp;&lt;STRONG&gt;Event A&lt;/STRONG&gt; rather than just look at &lt;STRONG&gt;Event B&lt;/STRONG&gt; and &lt;STRONG&gt;Event C&lt;/STRONG&gt; is because there are numerous occurrences of&amp;nbsp;&lt;STRONG&gt;Event B&lt;/STRONG&gt;&amp;nbsp;that are unrelated, so I first have to ensure they can be associated with an &lt;STRONG&gt;Event A&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;TLDR! I need the list of&amp;nbsp;&lt;STRONG&gt;personId&lt;/STRONG&gt; values that come from&amp;nbsp;&lt;STRONG&gt;Event C&lt;/STRONG&gt;, but first I need to make sure they are associated with&amp;nbsp;&lt;STRONG&gt;Event A&lt;/STRONG&gt; and&amp;nbsp;&lt;STRONG&gt;Event B &lt;/STRONG&gt;— the challenge being there is no one value contained by all three.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2020 17:27:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Using-three-events-without-common-fields-to-get-list-of-IDs/m-p/520900#M146736</guid>
      <dc:creator>RyanJWilliams</dc:creator>
      <dc:date>2020-09-22T17:27:36Z</dc:date>
    </item>
    <item>
      <title>Re: Using three events without common fields to get list of IDs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Using-three-events-without-common-fields-to-get-list-of-IDs/m-p/520902#M146738</link>
      <description>&lt;P&gt;If it helps, here is roughly what I did to achieve this using transaction, but because I need to run it over months this very quickly exhausts Splunk's event limits:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;(Event A)
OR (Event B)
OR (Event C)
| transaction correlationId
| where Event B OR Event C
| transaction req_id
| where Event C
| where personId!=""
| stats count by personId&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 22 Sep 2020 17:30:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Using-three-events-without-common-fields-to-get-list-of-IDs/m-p/520902#M146738</guid>
      <dc:creator>RyanJWilliams</dc:creator>
      <dc:date>2020-09-22T17:30:02Z</dc:date>
    </item>
    <item>
      <title>Re: Using three events without common fields to get list of IDs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Using-three-events-without-common-fields-to-get-list-of-IDs/m-p/520942#M146753</link>
      <description>&lt;P&gt;Try something like this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;-- your search with all types of events
| eventstats values(correlationId) as correlationId by req_id
| eventstats values(personId) as personId by correlationId&lt;/LI-CODE&gt;&lt;P&gt;Event A should now have all three ids&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2020 22:42:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Using-three-events-without-common-fields-to-get-list-of-IDs/m-p/520942#M146753</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-09-22T22:42:14Z</dc:date>
    </item>
  </channel>
</rss>

