Splunk Search

Compare Fields from Different Indexes and display only the duplicates.

ocgovsplunk
Engager

Hi,

I have two searches index= windows EventCode=1234 Logon_Type=8 | table host | dedup host
and index=iis host=*|table host|dedup host

How to combine both these queries to display only the hosts which have that particular EventCode and Type and also in the IIS index.

Thanks in advance.

0 Karma

skoelpin
SplunkTrust
SplunkTrust

Try something like this

(index=windows EventCode=1234 Logon_Type=8) OR (index=iis host=*)
| stats values(index) AS index by host 
0 Karma

ocgovsplunk
Engager

Thanks,

The above query is displaying the hosts which is either in index=windows or index=iis. I am looking for a list of only the hosts which are present in both the indexes.

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...