Deployment Architecture

Compare records from two different indexes by match

New Member

Hello community,

i have two databases a and b. There are data fields which I would like to compare with each other. What does such a query look like?
Each field must be compared with each field of the database b during adjustment. Important the match must not exactli by field in index b.

Match result positiv:

Index A:

Index B:

Who can help me?

Im a beginner into the splunk world...

Thank you

Tags (1)
0 Karma


Typically, that is done like this

index=A OR index=B | stats values(*) as * by field

but that requires and exact match of 'field' in each index. So what you'll need to do is massage field into something Splunk can compare.

index=A OR index=B | eval newfield=<something that normalizes field> | stats values(*) as * by newfield

or use rex to normalize the field

index=A OR index=B | rex field=field "(?<newfield>something)" | stats values(*) as * by newfield

I'll leave the "something" up to you since only you know how to compare the data in each index.

If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...

Observability Highlights | January 2023 Newsletter

 January 2023New Product Releases Splunk Network Explorer for Infrastructure MonitoringSplunk unveils Network ...

Security Highlights | January 2023 Newsletter

January 2023 Splunk Security Essentials (SSE) 3.7.0 ReleaseThe free Splunk Security Essentials (SSE) 3.7.0 app ...