<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Extract data from 2 different logs in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Extract-data-from-2-different-logs/m-p/685954#M234051</link>
    <description>&lt;P&gt;It works, thank you very much. One more thing, time filter isn't work, I mean if I set for 24H, search return logs for all time&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 30 Apr 2024 10:49:25 GMT</pubDate>
    <dc:creator>chimuru84</dc:creator>
    <dc:date>2024-04-30T10:49:25Z</dc:date>
    <item>
      <title>Extract data from 2 different logs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-data-from-2-different-logs/m-p/685946#M234045</link>
      <description>&lt;P&gt;Hello community!&lt;/P&gt;&lt;P&gt;I want to extract data from 2 different logs like bellow:&lt;/P&gt;&lt;P&gt;Log 1: 2024-04-28 06:38:51 INFO Start auth for accountId=1, ip=192.168.1.1&lt;/P&gt;&lt;P&gt;Log 2: 2024-04-28 06:38:27 INFO Collect response for accountId=1, was: response=FINISH&lt;/P&gt;&lt;P&gt;For example for accountId=1 I have 10 logs with "Start auth", I mean 10 attempts of start auth.&lt;/P&gt;&lt;P&gt;In second log, for the same accountId I have 1 or more logs with FINISH.&lt;/P&gt;&lt;P&gt;I want to make a table like&lt;/P&gt;&lt;P&gt;accountId&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Start auth&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; FINISH&lt;/P&gt;&lt;P&gt;1&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;10&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you helm me with this?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2024 09:34:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-data-from-2-different-logs/m-p/685946#M234045</guid>
      <dc:creator>chimuru84</dc:creator>
      <dc:date>2024-04-30T09:34:58Z</dc:date>
    </item>
    <item>
      <title>Re: Extract data from 2 different logs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-data-from-2-different-logs/m-p/685949#M234048</link>
      <description>&lt;P&gt;Have you already extracted accountId and response? If response does not have any value (null) does the event come from log1? If so, you could try something like this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eval state=coalesce(response, "Start auth")
| chart count by accountId state&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 30 Apr 2024 10:08:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-data-from-2-different-logs/m-p/685949#M234048</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-04-30T10:08:43Z</dc:date>
    </item>
    <item>
      <title>Re: Extract data from 2 different logs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-data-from-2-different-logs/m-p/685954#M234051</link>
      <description>&lt;P&gt;It works, thank you very much. One more thing, time filter isn't work, I mean if I set for 24H, search return logs for all time&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2024 10:49:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-data-from-2-different-logs/m-p/685954#M234051</guid>
      <dc:creator>chimuru84</dc:creator>
      <dc:date>2024-04-30T10:49:25Z</dc:date>
    </item>
    <item>
      <title>Re: Extract data from 2 different logs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Extract-data-from-2-different-logs/m-p/685955#M234052</link>
      <description>&lt;P&gt;This is a different question. Please start a new question with as much detail as possible.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2024 10:51:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Extract-data-from-2-different-logs/m-p/685955#M234052</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-04-30T10:51:54Z</dc:date>
    </item>
  </channel>
</rss>

