<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to tie in 2 different event sources to display a field value from one source based on a value from the other sou in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-tie-in-2-different-event-sources-to-display-a-field-value/m-p/704308#M238671</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Thanks for your help,&amp;nbsp; I am hoping for a way in the search to say something like if name from first query = servername1 then name from second query = teamname1.&amp;nbsp; But, have no idea how to achieve that.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;</description>
    <pubDate>Wed, 13 Nov 2024 17:05:33 GMT</pubDate>
    <dc:creator>mninansplunk</dc:creator>
    <dc:date>2024-11-13T17:05:33Z</dc:date>
    <item>
      <title>How to tie in 2 different event sources to display a field value from one source based on a value from the other source.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-tie-in-2-different-event-sources-to-display-a-field-value/m-p/704302#M238669</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Sorry, still trying to get the hang of Search queries.&amp;nbsp; &amp;nbsp;I am tasked with creating a table that displays a server name from one search, with a team name from another search that corresponds with the server name.&amp;nbsp; In example,&lt;/P&gt;&lt;P&gt;1st Search&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="netscaler | table servername&lt;/LI-CODE&gt;&lt;P&gt;Results in a table like:&lt;/P&gt;&lt;P&gt;servername1&lt;/P&gt;&lt;P&gt;servername2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2nd Search&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="main | table teamname&lt;/LI-CODE&gt;&lt;P&gt;Results in a table like&lt;/P&gt;&lt;P&gt;teamname1&lt;/P&gt;&lt;P&gt;teamname2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to make 1 table that will display the corresponding teamname to the servername.&amp;nbsp; Like If servername = servername2, display teamname2 in the same table row.&lt;/P&gt;&lt;P&gt;Does that make sense. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp; Let me know if any details are needed.&amp;nbsp; Not sure how to do this one.&lt;/P&gt;&lt;P&gt;Thanks for any help,&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2024 16:08:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-tie-in-2-different-event-sources-to-display-a-field-value/m-p/704302#M238669</guid>
      <dc:creator>mninansplunk</dc:creator>
      <dc:date>2024-11-13T16:08:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to tie in 2 different event sources to display a field value from one source based on a value from the other sou</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-tie-in-2-different-event-sources-to-display-a-field-value/m-p/704305#M238670</link>
      <description>&lt;P&gt;The two searches have no obvious relationship to each other.&amp;nbsp; How is Splunk to know how to match a server name to a team name?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2024 16:39:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-tie-in-2-different-event-sources-to-display-a-field-value/m-p/704305#M238670</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-11-13T16:39:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to tie in 2 different event sources to display a field value from one source based on a value from the other sou</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-tie-in-2-different-event-sources-to-display-a-field-value/m-p/704308#M238671</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Thanks for your help,&amp;nbsp; I am hoping for a way in the search to say something like if name from first query = servername1 then name from second query = teamname1.&amp;nbsp; But, have no idea how to achieve that.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2024 17:05:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-tie-in-2-different-event-sources-to-display-a-field-value/m-p/704308#M238671</guid>
      <dc:creator>mninansplunk</dc:creator>
      <dc:date>2024-11-13T17:05:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to tie in 2 different event sources to display a field value from one source based on a value from the other sou</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-tie-in-2-different-event-sources-to-display-a-field-value/m-p/704310#M238672</link>
      <description>&lt;P&gt;It might be helpful if you shared some sample (anonymised) events from your searches, preferably in raw format in codeblocks (using the &amp;lt;/&amp;gt; button above)&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2024 17:09:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-tie-in-2-different-event-sources-to-display-a-field-value/m-p/704310#M238672</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-11-13T17:09:47Z</dc:date>
    </item>
    <item>
      <title>Re: How to tie in 2 different event sources to display a field value from one source based on a value from the other sou</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-tie-in-2-different-event-sources-to-display-a-field-value/m-p/704312#M238673</link>
      <description>&lt;P&gt;Yes, you said that in the OP, but what is the logic behind that matching?&amp;nbsp; The query needs an algorithm it can use to pair servers with teams.&amp;nbsp; Otherwise, you're looking at creating a lookup table that does the matching.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2024 17:10:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-tie-in-2-different-event-sources-to-display-a-field-value/m-p/704312#M238673</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-11-13T17:10:28Z</dc:date>
    </item>
  </channel>
</rss>

