- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Correlating events from 2 different indexers when there is no common field
vijaya5
Engager
04-14-2020
02:44 AM
Hi,
I have 2 different indexers snmptrapd and servicenow.
Where snmptrap will have NNMI related events for storage devices, such as when any storage device is down/not functional
and servicenow indexer will have incident related events from CMDB data.
So i need to get events with storage device down along with respective Incident data.
Is there any possibility to correlate these 2 indexers, so that i can get required
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

richgalloway

SplunkTrust
04-14-2020
05:42 AM
I believe "indexers" is mis-used here and should be "indexes".
---
If this reply helps you, Karma would be appreciated.
If this reply helps you, Karma would be appreciated.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

harishalipaka
Motivator
04-14-2020
03:15 AM
@vijaya5
Can you provide sample data ?
Thanks
Harish
Harish
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

kamlesh_vaghela

SplunkTrust
04-14-2020
05:18 AM
with expected results 🙂
