<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Search using two indexes in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Search-using-two-indexes/m-p/553275#M157069</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/230148"&gt;@moayadalghamdi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;try this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=msexchange OR index=cisco_esa | stats  values(message_subject) as message_subject values(sender) as sender by src_ip&lt;/LI-CODE&gt;</description>
    <pubDate>Thu, 27 May 2021 08:42:41 GMT</pubDate>
    <dc:creator>aasabatini</dc:creator>
    <dc:date>2021-05-27T08:42:41Z</dc:date>
    <item>
      <title>Search using two indexes</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-using-two-indexes/m-p/553274#M157068</link>
      <description>&lt;P&gt;Hola Splunkers !!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i want to search in two indexes with one common values in between, for exapmle:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;index=Exchange_server has the following fields: &lt;EM&gt;&lt;STRONG&gt;sender&lt;/STRONG&gt;&lt;/EM&gt;, subject&lt;/P&gt;&lt;P&gt;index=EmailProxy&amp;nbsp;has the following fields: src_ip, &lt;EM&gt;&lt;STRONG&gt;sender&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;where the&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;sender&lt;/STRONG&gt; &lt;/EM&gt;value is the same in the two indexes&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i want the output to conclude: src_ip,&amp;nbsp;SenderMail,&amp;nbsp; Subject&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;here's my search:&lt;/P&gt;&lt;P&gt;index=Exchange_server OR index=EmailProxy&amp;nbsp;| table src_ip message_subjec sender&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="moayadalghamdi_0-1622103988354.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14331i922C3176FEC16116/image-size/medium?v=v2&amp;amp;px=400" role="button" title="moayadalghamdi_0-1622103988354.png" alt="moayadalghamdi_0-1622103988354.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but unfortunately i got many blank fields, please help me with it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks^_^&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 May 2021 08:48:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-using-two-indexes/m-p/553274#M157068</guid>
      <dc:creator>moayadalghamdi</dc:creator>
      <dc:date>2021-05-27T08:48:08Z</dc:date>
    </item>
    <item>
      <title>Re: Search using two indexes</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-using-two-indexes/m-p/553275#M157069</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/230148"&gt;@moayadalghamdi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;try this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=msexchange OR index=cisco_esa | stats  values(message_subject) as message_subject values(sender) as sender by src_ip&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 27 May 2021 08:42:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-using-two-indexes/m-p/553275#M157069</guid>
      <dc:creator>aasabatini</dc:creator>
      <dc:date>2021-05-27T08:42:41Z</dc:date>
    </item>
  </channel>
</rss>

