Splunk Search

Compare Fields from Different Indexes and display only the duplicates.

Engager

Hi,

I have two searches index= windows EventCode=1234 Logon_Type=8 | table host | dedup host
and index=iis host=*|table host|dedup host

How to combine both these queries to display only the hosts which have that particular EventCode and Type and also in the IIS index.

Thanks in advance.

0 Karma

SplunkTrust
SplunkTrust

Try something like this

(index=windows EventCode=1234 Logon_Type=8) OR (index=iis host=*)
| stats values(index) AS index by host 
0 Karma

Engager

Thanks,

The above query is displaying the hosts which is either in index=windows or index=iis. I am looking for a list of only the hosts which are present in both the indexes.

0 Karma