Hi Splunkers,
There is one field is common in 2 indexes. Using that field how can i co-relate and make a table out of it without using JOIN, Append & Appendpipe command ? Because those command will take a lot of time and
Please refer to the below pictures
Thanks & regards
Can you please try this?
index=IDX1 OR index=IDX2 | stats values(User_IP) as User_IP,values(Action) as Action, values(Comments) as Comments by ID
Change the index name and field name as per your requirement.
KV
AKA- GOKU
Can you please try this?
index=IDX1 OR index=IDX2 | stats values(User_IP) as User_IP,values(Action) as Action, values(Comments) as Comments by ID
Change the index name and field name as per your requirement.
KV
AKA- GOKU
But there is only one problem.
I am getting multiple comments values in a single table events.
Can we segregate that as well ?
Are you a magician?
Because your magic spell(SPL) actually worked without giving any errors.
Thanks much
Glad to help you. 😀 . If the solution resolved your problem then please accept the answer to the close question.
KV