<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Help with Splunk search to join two searches with common field in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Help-with-Splunk-search-to-join-two-searches-with-common-field/m-p/554921#M157498</link>
    <description>&lt;P&gt;These are all events from Splunk Nix TA add-on which&amp;nbsp; gives var/logs top , ps&amp;nbsp; &amp;nbsp;etc logs . The events that I posted are all related to var/logs .&lt;/P&gt;&lt;P&gt;Event 1 is data related to sudo authentication success logs which&amp;nbsp; host and user name data .Event 2 is data related to password entered and accepted for the sudo login which has host , user name the source ip and source port .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to get the user who has logged into as host as sudo user ,source ip , source port .&lt;/P&gt;&lt;P&gt;Sample event 1 - sudo login&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;Jun&lt;/SPAN&gt; &lt;SPAN class="t"&gt;7&lt;/SPAN&gt; &lt;SPAN class="t"&gt;14:55:37&lt;/SPAN&gt; &lt;SPAN class="t"&gt;v***&lt;/SPAN&gt; &lt;SPAN class="t"&gt;&lt;SPAN class="t a"&gt;sudo&lt;/SPAN&gt;:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;pam_sss&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN class="t"&gt;&lt;SPAN class="t a"&gt;sudo&lt;/SPAN&gt;:auth&lt;/SPAN&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;authentication&lt;/SPAN&gt; &lt;SPAN class="t"&gt;success&lt;/SPAN&gt;&lt;SPAN&gt;; &lt;/SPAN&gt;&lt;SPAN class="t"&gt;logname=lq&lt;/SPAN&gt; &lt;SPAN class="t"&gt;uid=5123&lt;/SPAN&gt; &lt;SPAN class="t"&gt;euid=0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;tty=/dev/pts/0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;ruser=lq&lt;/SPAN&gt; &lt;SPAN class="t"&gt;rhost=&lt;/SPAN&gt; &lt;SPAN class="t"&gt;user=lq&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;Sample event 2 - password accepted&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;Jun&amp;nbsp;7&amp;nbsp;14:31:30 v*** sshd&lt;SPAN&gt;[&lt;/SPAN&gt;62591&lt;SPAN&gt;]&lt;/SPAN&gt;: &lt;SPAN class="t a"&gt;Accepted&lt;/SPAN&gt; &lt;SPAN class="t a"&gt;password&lt;/SPAN&gt; for lq from 10.**.*.1 port 6***5 ssh&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 08 Jun 2021 14:19:35 GMT</pubDate>
    <dc:creator>vrmandadi</dc:creator>
    <dc:date>2021-06-08T14:19:35Z</dc:date>
    <item>
      <title>Help with Splunk search to join two searches with common field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-Splunk-search-to-join-two-searches-with-common-field/m-p/554759#M157462</link>
      <description>&lt;P&gt;I am trying to&amp;nbsp; join two searches with a common field&lt;/P&gt;&lt;P&gt;Event1:&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;Jun&lt;/SPAN&gt; &lt;SPAN class="t"&gt;7&lt;/SPAN&gt; &lt;SPAN class="t"&gt;14:55:37&lt;/SPAN&gt; &lt;STRONG&gt;&lt;SPAN class="t"&gt;v3**v&lt;/SPAN&gt;&lt;/STRONG&gt; &lt;SPAN class="t"&gt;&lt;SPAN class="t a"&gt;sudo&lt;/SPAN&gt;:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;pam_sss&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN class="t"&gt;&lt;SPAN class="t a"&gt;sudo&lt;/SPAN&gt;:auth&lt;/SPAN&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;authentication&lt;/SPAN&gt; &lt;SPAN class="t"&gt;success&lt;/SPAN&gt;&lt;SPAN&gt;; &lt;/SPAN&gt;&lt;SPAN class="t"&gt;logname=l*&lt;/SPAN&gt; &lt;SPAN class="t"&gt;uid=5123&lt;/SPAN&gt; &lt;SPAN class="t"&gt;euid=0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;tty=/dev/pts/0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;ruser=lab&lt;/SPAN&gt; &lt;SPAN class="t"&gt;rhost=&lt;/SPAN&gt; &lt;STRONG&gt;&lt;SPAN class="t h"&gt;&lt;SPAN class="t"&gt;user&lt;/SPAN&gt;=&lt;SPAN class="t"&gt;lab&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t h"&gt;&lt;SPAN class="t"&gt;Event2:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t h"&gt;&lt;SPAN class="t"&gt;Jun 7 14:48:38 v3**v-adm sshd&lt;SPAN&gt;[&lt;/SPAN&gt;14821&lt;SPAN&gt;]&lt;/SPAN&gt;: &lt;SPAN class="t a"&gt;Accepted&lt;/SPAN&gt; &lt;SPAN class="t a"&gt;password&lt;/SPAN&gt; for lab from &lt;STRONG&gt;10.**.**.**&lt;/STRONG&gt;&amp;nbsp;port &lt;STRONG&gt;4***4&lt;/STRONG&gt; ssh2&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t h"&gt;&lt;SPAN class="t"&gt;I want to merge two events with common field as host which is&amp;nbsp;v3**v in the events and output&amp;nbsp; the host,user(lab),ip(v3**v) and port (***4)&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t h"&gt;&lt;SPAN class="t"&gt;Thanks in advance&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jun 2021 19:21:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-Splunk-search-to-join-two-searches-with-common-field/m-p/554759#M157462</guid>
      <dc:creator>vrmandadi</dc:creator>
      <dc:date>2021-06-07T19:21:45Z</dc:date>
    </item>
    <item>
      <title>Re: Help with Splunk search to join two searches with common field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-Splunk-search-to-join-two-searches-with-common-field/m-p/554779#M157464</link>
      <description>&lt;P&gt;Are these events from the same index/search? Which fields do you already have extracted? Is the field with v3**v-adm always in two parts separated by "-"? Can you provide more example events?&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jun 2021 21:05:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-Splunk-search-to-join-two-searches-with-common-field/m-p/554779#M157464</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-06-07T21:05:50Z</dc:date>
    </item>
    <item>
      <title>Re: Help with Splunk search to join two searches with common field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-Splunk-search-to-join-two-searches-with-common-field/m-p/554799#M157472</link>
      <description>&lt;P&gt;Yes both are from same index and same source type ... Yes everything is extracted.I an trying to see what is the best way to join so that I can get the IP and port details from the second event and merge with host ,user using host as common field .&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jun 2021 01:14:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-Splunk-search-to-join-two-searches-with-common-field/m-p/554799#M157472</guid>
      <dc:creator>vrmandadi</dc:creator>
      <dc:date>2021-06-08T01:14:19Z</dc:date>
    </item>
    <item>
      <title>Re: Help with Splunk search to join two searches with common field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-Splunk-search-to-join-two-searches-with-common-field/m-p/554833#M157481</link>
      <description>&lt;P&gt;If you are not going to give us more useful details, all I can suggest is you try&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| stats values(ip) as ip values(port) as port values(user) as user by host&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jun 2021 06:44:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-Splunk-search-to-join-two-searches-with-common-field/m-p/554833#M157481</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-06-08T06:44:02Z</dc:date>
    </item>
    <item>
      <title>Re: Help with Splunk search to join two searches with common field</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-Splunk-search-to-join-two-searches-with-common-field/m-p/554921#M157498</link>
      <description>&lt;P&gt;These are all events from Splunk Nix TA add-on which&amp;nbsp; gives var/logs top , ps&amp;nbsp; &amp;nbsp;etc logs . The events that I posted are all related to var/logs .&lt;/P&gt;&lt;P&gt;Event 1 is data related to sudo authentication success logs which&amp;nbsp; host and user name data .Event 2 is data related to password entered and accepted for the sudo login which has host , user name the source ip and source port .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to get the user who has logged into as host as sudo user ,source ip , source port .&lt;/P&gt;&lt;P&gt;Sample event 1 - sudo login&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;Jun&lt;/SPAN&gt; &lt;SPAN class="t"&gt;7&lt;/SPAN&gt; &lt;SPAN class="t"&gt;14:55:37&lt;/SPAN&gt; &lt;SPAN class="t"&gt;v***&lt;/SPAN&gt; &lt;SPAN class="t"&gt;&lt;SPAN class="t a"&gt;sudo&lt;/SPAN&gt;:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;pam_sss&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN class="t"&gt;&lt;SPAN class="t a"&gt;sudo&lt;/SPAN&gt;:auth&lt;/SPAN&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;authentication&lt;/SPAN&gt; &lt;SPAN class="t"&gt;success&lt;/SPAN&gt;&lt;SPAN&gt;; &lt;/SPAN&gt;&lt;SPAN class="t"&gt;logname=lq&lt;/SPAN&gt; &lt;SPAN class="t"&gt;uid=5123&lt;/SPAN&gt; &lt;SPAN class="t"&gt;euid=0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;tty=/dev/pts/0&lt;/SPAN&gt; &lt;SPAN class="t"&gt;ruser=lq&lt;/SPAN&gt; &lt;SPAN class="t"&gt;rhost=&lt;/SPAN&gt; &lt;SPAN class="t"&gt;user=lq&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;Sample event 2 - password accepted&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;Jun&amp;nbsp;7&amp;nbsp;14:31:30 v*** sshd&lt;SPAN&gt;[&lt;/SPAN&gt;62591&lt;SPAN&gt;]&lt;/SPAN&gt;: &lt;SPAN class="t a"&gt;Accepted&lt;/SPAN&gt; &lt;SPAN class="t a"&gt;password&lt;/SPAN&gt; for lq from 10.**.*.1 port 6***5 ssh&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jun 2021 14:19:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-Splunk-search-to-join-two-searches-with-common-field/m-p/554921#M157498</guid>
      <dc:creator>vrmandadi</dc:creator>
      <dc:date>2021-06-08T14:19:35Z</dc:date>
    </item>
  </channel>
</rss>

