Archive

Compare field value from different sourcetypes to list the value of the third field

New Member

Hi All,
i have 2 files indexed as 2 different source types.
In Sourcetype1 i created:
1. Field1 presents the value of a file let's say example.txt
2. Field2 presents the value of the result let's say [OK]

In Sourcetype2 i created:
Field1 presents the value of a file let's say example.txt

I would like to create a search that
If Field1 value from sourcetype1 = Field1 value from sourcetype2 list Field2 value from sourcetype1

My final goal is to create a table that lists the event details (time, user, files, results) the last column will be the result that is a little bit more trickier to achieve.

Thanks A Lot Guys!

Tags (1)
0 Karma

SplunkTrust
SplunkTrust

There probably are a few ways to do that. Here's one.

sourcetype=sourcetype1 OR sourcetype=sourcetype2 | stats values(Field2) by Field1
---
If this reply helps you, an upvote would be appreciated.
0 Karma
Don’t Miss Global Splunk
User Groups Week!

Free LIVE events worldwide 2/8-2/12
Connect, learn, and collect rad prizes
and swag!