<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Relative pattern matching in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Relative-pattern-matching/m-p/368053#M164121</link>
    <description>&lt;P&gt;It's not clear what you hope to achieve.  What do you mean by "relative pattern"?  Given those two sources, what do you want the search results to be?&lt;/P&gt;</description>
    <pubDate>Thu, 28 Dec 2017 18:32:01 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2017-12-28T18:32:01Z</dc:date>
    <item>
      <title>Relative pattern matching</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Relative-pattern-matching/m-p/368052#M164120</link>
      <description>&lt;P&gt;I am trying to do relative searches over multiple sources. I want to be able search source1 in source2 or vice versa to the closest match. For example &lt;BR /&gt;
Source1:&lt;/P&gt;

&lt;P&gt;Publisher   Name            Version&lt;BR /&gt;
Microsoft   SQL Server     2008&lt;BR /&gt;
Microsft     Office              2010&lt;/P&gt;

&lt;P&gt;Source2:&lt;BR /&gt;
Product&lt;BR /&gt;
Microsoft SQL Server Common Files&lt;BR /&gt;
Microsoft SQL Server 2012&lt;BR /&gt;
Microsoft SQL Server 2008&lt;BR /&gt;
Any help would be appreciated.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Dec 2017 17:37:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Relative-pattern-matching/m-p/368052#M164120</guid>
      <dc:creator>pmehta77</dc:creator>
      <dc:date>2017-12-28T17:37:37Z</dc:date>
    </item>
    <item>
      <title>Re: Relative pattern matching</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Relative-pattern-matching/m-p/368053#M164121</link>
      <description>&lt;P&gt;It's not clear what you hope to achieve.  What do you mean by "relative pattern"?  Given those two sources, what do you want the search results to be?&lt;/P&gt;</description>
      <pubDate>Thu, 28 Dec 2017 18:32:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Relative-pattern-matching/m-p/368053#M164121</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2017-12-28T18:32:01Z</dc:date>
    </item>
    <item>
      <title>Re: Relative pattern matching</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Relative-pattern-matching/m-p/368054#M164122</link>
      <description>&lt;P&gt;Ok. Let me try to clarify it again. So i am looking for a relative match between , for example ,  IBM Tivoli Endpoint Manager and IBM Endpoint Manager. The reason its a relative match is because only one word &lt;BR /&gt;
"Tivoli "is missing from name in source2. Similarly if i have Oracle JBEA Rocket in Source1 and Source2 has "BEA Rocket" that should be a close match. I hope that clarifies otherwise i will make another example. My personal thought was that i need to use a Fuzzy search mechanism or a cluster search that can bring out matching event types. But I am not sure how to apply that across multiple sources.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Dec 2017 21:16:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Relative-pattern-matching/m-p/368054#M164122</guid>
      <dc:creator>pmehta77</dc:creator>
      <dc:date>2017-12-28T21:16:10Z</dc:date>
    </item>
    <item>
      <title>Re: Relative pattern matching</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Relative-pattern-matching/m-p/368055#M164123</link>
      <description>&lt;P&gt;There is a &lt;A href="https://splunkbase.splunk.com/app/1898/"&gt;Levenshtein&lt;/A&gt; app for Splunk.  It makes use of &lt;A href="https://en.wikipedia.org/wiki/Levenshtein_distance"&gt;Levenshtein distance&lt;/A&gt;, which sounds like it may suit your needs.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Dec 2017 21:24:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Relative-pattern-matching/m-p/368055#M164123</guid>
      <dc:creator>micahkemp</dc:creator>
      <dc:date>2017-12-28T21:24:04Z</dc:date>
    </item>
  </channel>
</rss>

