<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to search for events based on certain field and its exclusive values between two searches? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-search-for-events-based-on-certain-field-and-its/m-p/225644#M66542</link>
    <description>&lt;P&gt;Say I have two searches on data sets which contain four fields  [field1, field2, field3, field4], e.g.&lt;BR /&gt;&lt;BR /&gt;
[1,20,am,a]&lt;BR /&gt;
[1,20,am,b] &lt;BR /&gt;
[1,20,pm,b]&lt;BR /&gt;
[1,20,pm,c]&lt;/P&gt;

&lt;P&gt;Search 1: field1 = 1, field2 = 20, field3 = am will return  [1,20,am,a] and  [1,20,am,b]&lt;BR /&gt;
Search 2: field1 = 1, field2 = 20, field3 = pm will return [1,20,pm, b] and [1,20,pm,c]&lt;/P&gt;

&lt;P&gt;Yet I'm interested in field4 and those events with values of field4 exclusively in my first search, i.e.  [1,2,am,a] in this case since field4=b is also presented in second search.&lt;/P&gt;

&lt;P&gt;What would be an efficient way to do so? Thanks a lot!&lt;/P&gt;</description>
    <pubDate>Wed, 22 Jun 2016 23:16:17 GMT</pubDate>
    <dc:creator>FallMonkey</dc:creator>
    <dc:date>2016-06-22T23:16:17Z</dc:date>
    <item>
      <title>How to search for events based on certain field and its exclusive values between two searches?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-search-for-events-based-on-certain-field-and-its/m-p/225644#M66542</link>
      <description>&lt;P&gt;Say I have two searches on data sets which contain four fields  [field1, field2, field3, field4], e.g.&lt;BR /&gt;&lt;BR /&gt;
[1,20,am,a]&lt;BR /&gt;
[1,20,am,b] &lt;BR /&gt;
[1,20,pm,b]&lt;BR /&gt;
[1,20,pm,c]&lt;/P&gt;

&lt;P&gt;Search 1: field1 = 1, field2 = 20, field3 = am will return  [1,20,am,a] and  [1,20,am,b]&lt;BR /&gt;
Search 2: field1 = 1, field2 = 20, field3 = pm will return [1,20,pm, b] and [1,20,pm,c]&lt;/P&gt;

&lt;P&gt;Yet I'm interested in field4 and those events with values of field4 exclusively in my first search, i.e.  [1,2,am,a] in this case since field4=b is also presented in second search.&lt;/P&gt;

&lt;P&gt;What would be an efficient way to do so? Thanks a lot!&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2016 23:16:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-search-for-events-based-on-certain-field-and-its/m-p/225644#M66542</guid>
      <dc:creator>FallMonkey</dc:creator>
      <dc:date>2016-06-22T23:16:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to search for events based on certain field and its exclusive values between two searches?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-search-for-events-based-on-certain-field-and-its/m-p/225645#M66543</link>
      <description>&lt;P&gt;Can you try to clarify a little bit more of what you're looking for here? I don't see field4 mentioned in either of your searches &lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2016 01:55:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-search-for-events-based-on-certain-field-and-its/m-p/225645#M66543</guid>
      <dc:creator>ryanoconnor</dc:creator>
      <dc:date>2016-06-23T01:55:01Z</dc:date>
    </item>
    <item>
      <title>Re: How to search for events based on certain field and its exclusive values between two searches?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-search-for-events-based-on-certain-field-and-its/m-p/225646#M66544</link>
      <description>&lt;P&gt;Thanks for the reply! &lt;/P&gt;

&lt;P&gt;Yes field4 is not listed as my search keyword but it's inside the event/data sets. One event actually contains much more fields but the ones I listed are most interesting for me. Please lemme know if you need more information.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2016 02:52:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-search-for-events-based-on-certain-field-and-its/m-p/225646#M66544</guid>
      <dc:creator>FallMonkey</dc:creator>
      <dc:date>2016-06-23T02:52:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to search for events based on certain field and its exclusive values between two searches?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-search-for-events-based-on-certain-field-and-its/m-p/225647#M66545</link>
      <description>&lt;P&gt;You have not been clear at all.  Please start over, show us COMPLETE sample events and then desired final output.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2016 06:42:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-search-for-events-based-on-certain-field-and-its/m-p/225647#M66545</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2016-06-23T06:42:44Z</dc:date>
    </item>
    <item>
      <title>Re: How to search for events based on certain field and its exclusive values between two searches?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-search-for-events-based-on-certain-field-and-its/m-p/225648#M66546</link>
      <description>&lt;P&gt;Sorry for not being clear. I've edited my question with more concrete samples for your information.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2016 07:15:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-search-for-events-based-on-certain-field-and-its/m-p/225648#M66546</guid>
      <dc:creator>FallMonkey</dc:creator>
      <dc:date>2016-06-23T07:15:32Z</dc:date>
    </item>
    <item>
      <title>Re: How to search for events based on certain field and its exclusive values between two searches?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-search-for-events-based-on-certain-field-and-its/m-p/225649#M66547</link>
      <description>&lt;P&gt;You have made a minor adjustment to YOUR plan (not working) and ignored MY plan (which would have gotten you an answer instead of snark).  Let me take a stab and you tell me if I am guessing anything remotely close (I am a nerd, not a mind reader):&lt;/P&gt;

&lt;P&gt;I am interested in taking running a search where I specify values for 3 fields and extracting from that search the values of a 4th field.  I would then like to use those values to drive another search.&lt;/P&gt;

&lt;P&gt;In the case of the example data above, the first search is &lt;CODE&gt;1: field1 = 1, field2 = 20, field3 = am&lt;/CODE&gt; and will return &lt;CODE&gt;[1,20,am,a] and [1,20,am,b]&lt;/CODE&gt;&lt;BR /&gt;
These events with values &lt;CODE&gt;a&lt;/CODE&gt; and &lt;CODE&gt;b&lt;/CODE&gt; for field &lt;CODE&gt;field4&lt;/CODE&gt;.  Now I would like to use those values to drive another search like this: &lt;CODE&gt;field1 = 1, field2 = 20, field3 = pm (field4=b OR field4=c)&lt;/CODE&gt; which would return &lt;CODE&gt;[1,20,pm, b]&lt;/CODE&gt;.&lt;/P&gt;

&lt;P&gt;How can I do this all in a single search?&lt;/P&gt;

&lt;P&gt;See how I gave specific final desired output?  I know that my guess is probably wrong, but why are you making us guess?&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2016 17:47:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-search-for-events-based-on-certain-field-and-its/m-p/225649#M66547</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2016-06-23T17:47:24Z</dc:date>
    </item>
    <item>
      <title>Re: How to search for events based on certain field and its exclusive values between two searches?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-search-for-events-based-on-certain-field-and-its/m-p/225650#M66548</link>
      <description>&lt;P&gt;Thanks a lot for the comment. Again sorry for the confusion caused here.&lt;/P&gt;

&lt;P&gt;I wish to run two similar searches first, as shown above. Then in the results there will be some events with same value of field4 between two search results.&lt;/P&gt;

&lt;P&gt;From there I wish to run another search/filtering on complete dataset, to get rid of those events with values of field4 that show up in my 2nd search. Therefore [1,20,am,b] and [1,20,pm,b] are taken out because field4=b is in my 2nd search, as well as [1,20,pm,c]. Clearly I need first two searches to identify how values of field4 are distributed between two searches, so that I could start filter.&lt;/P&gt;

&lt;P&gt;Then my question is how I can do all of this in one line. Please lemme know if something is still unclear.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2016 18:02:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-search-for-events-based-on-certain-field-and-its/m-p/225650#M66548</guid>
      <dc:creator>FallMonkey</dc:creator>
      <dc:date>2016-06-23T18:02:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to search for events based on certain field and its exclusive values between two searches?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-search-for-events-based-on-certain-field-and-its/m-p/225651#M66549</link>
      <description>&lt;P&gt;Try this&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;"Your search1" | join type=outer field4 [search "your search2"]
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 23 Jun 2016 18:13:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-search-for-events-based-on-certain-field-and-its/m-p/225651#M66549</guid>
      <dc:creator>diogofgm</dc:creator>
      <dc:date>2016-06-23T18:13:34Z</dc:date>
    </item>
    <item>
      <title>Re: How to search for events based on certain field and its exclusive values between two searches?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-search-for-events-based-on-certain-field-and-its/m-p/225652#M66550</link>
      <description>&lt;P&gt;Like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=YourIndexHere sourcetype=YourSourcetypeHere field1 = "1" field2 = "20" (field3 = "am" OR field3 = "pm")
| stats dc(field3) AS numSources values(*) AS * BY field4
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;You now  have a fully joined set:&lt;BR /&gt;
For left Join, add this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; | search field3="am" AND numSources&amp;gt;1
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;For right join, add this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; | search field3="pm" AND numSources&amp;gt;1
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;For inner join, add this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| search numSources&amp;gt;1
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;For outer join, add this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| search numSources=1
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 23 Jun 2016 18:45:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-search-for-events-based-on-certain-field-and-its/m-p/225652#M66550</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2016-06-23T18:45:42Z</dc:date>
    </item>
  </channel>
</rss>

