All Apps and Add-ons

How to Cacatenate and Search in 2 different Sources

muru143
New Member

Hi Splunk Experts,

I have 2 files

File1:

Filer_Name    Dept     Volume_Name    Vol_Total    Vol_Used

Abcd                   Vol1           100          50

File 2:

Filer_Name    Dept     Volume_Name    Vol_Total    Vol_Used

Abcd          IT       Vol1

File 1 is generated by storage monitoring script and file 2 is maintained manually with Dept name.

What I want to do is, I want to concatenate “Filer_Name” and “Volume_Name” in both files and based on the value lookup for Dept in File2.
How can do this in Splunk?

I got to the point of concatenating the fields in file 1, but not sure how to do lookup based in concatenated value from file 2.

I have indexed both files in splunk.

Can anyone tell me if this is possible.

Thanks for your help,

Muru

0 Karma

muru143
New Member

basically I want to lookup a field from file2 by matching concatenation of fields "filer_name" and "vol_name" in file1 to concenation of same fields in file 2.

0 Karma

jrodman
Splunk Employee
Splunk Employee

I don't understand the question.

However you can concatenate fields with eval

... |eval newfield=field1 . field2

Typically if you want to use file2 as a table to enrich file1, it's more convenient to set up the data as a lookup. You could generate a lookup from file2 by doing some gymnastics like:

source=file2 | fields Filer_Name, Dept, Volume_Name |outputlookup my_lookup

you might have to set up some conf to comprehend your lookup for meaningful use.
More about lookups: http://docs.splunk.com/Documentation/Splunk/5.0.3/Knowledge/Addfieldsfromexternaldatasources

Once you have the lookup set up to work automatically or by invocation, it would become something like

source=file1 |lookup my_lookup | ...

where you may wish to filter the items to augment before or after the lookup.

0 Karma

muru143
New Member

Thanks, I was able to use lookup to accomplish what I wanted to do.

Thanks for your help,

-Muru

0 Karma

kristian_kolb
Ultra Champion

Many things are possible. Please show in more detail how you want the results presented. It's not really clear.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...