Getting Data In

How to add fields from one index to another with the same sourcetype?

Fritsch
New Member

I want to add fields from one Index to another, with the same sourcetype "stash"

In Index A there are fields like a, b, c, d,..

Thats what i did:

index="A" | stats count by a | sort -count | collct index="B"

The fields I get in index B are "a" and "count", but

how can I get the fields b, c, and d in the Index B?

Tags (3)
0 Karma

MuS
Legend

Hi Fritsch,

either re-run the command for each field like:

index="A" | stats count by a | sort -count | collect index="B"
index="A" | stats count by b | sort -count | collect index="B"
index="A" | stats count by c | sort -count | collect index="B"

or try something like this:

index="A" | stats count by a, b, c, d | sort -count | collect index="B"

or without a count field:

index="A" | table a, b, c, d | collect index="B"

hope this helps ...

cheers, MuS

Fritsch
New Member

Hi MuS,

thanks for your answer.

This command is allmost the one i need.

With the second command, b, c, g... is counted too, but i just want those fields to display in the stats.

Have you got any other idea?

Thanks so far.

0 Karma

MuS
Legend

Have you tried the command using the table as well? This should do what you want...

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...