Getting Data In

Joining two search based on closest time

eidil
Explorer

I am trying to join two searches based on closest time to match ticketnum with its real event e.g.

index=monitoring,

12:01:00 host=abc  status=down

3:05:00  host=abc status=down

index=ticket

12.03:00 host=abc  ticketnum=inc123

3:07:00 host=abc  ticketnum=inc456

Any idea on how to join these two based on closest time?

 

0 Karma
1 Solution

thambisetty
SplunkTrust
SplunkTrust

try something like below

 

index=monitoring OR index=ticket
| stats values(*) as * values(status) as status values(ticketnum) as ticketnum by _time, host
| streamstats last(status) as last_status by host
| fields - status
| where isnotnull(ticketnum)

 

 

Annotation 2020-09-08 082005.png 

like answer if it solves your problem.

————————————
If this helps, give a like below.

View solution in original post

thambisetty
SplunkTrust
SplunkTrust

that you would know which fields are required in report. I provided solution based on your query. please provide details.

————————————
If this helps, give a like below.
0 Karma

eidil
Explorer

Somethg like this

0 Karma

eidil
Explorer

eidil_0-1599720109186.png

 

0 Karma

thambisetty
SplunkTrust
SplunkTrust

@eidil 

check my updated answer : added values(*) as * to stats command

————————————
If this helps, give a like below.
0 Karma

thambisetty
SplunkTrust
SplunkTrust

try something like below

 

index=monitoring OR index=ticket
| stats values(*) as * values(status) as status values(ticketnum) as ticketnum by _time, host
| streamstats last(status) as last_status by host
| fields - status
| where isnotnull(ticketnum)

 

 

Annotation 2020-09-08 082005.png 

like answer if it solves your problem.

————————————
If this helps, give a like below.

eidil
Explorer

Hi @thambisetty , it seems d-able but the real logs are having much more details.  How do we know which fields needs to be written in the streamstats command?

0 Karma
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...