- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Compare field value from different sourcetypes to list the value of the third field
mardix86
New Member
01-06-2020
04:13 AM
Hi All,
i have 2 files indexed as 2 different source types.
In Sourcetype1 i created:
1. Field1 presents the value of a file let's say example.txt
2. Field2 presents the value of the result let's say [OK]
In Sourcetype2 i created:
Field1 presents the value of a file let's say example.txt
I would like to create a search that
If Field1 value from sourcetype1 = Field1 value from sourcetype2 list Field2 value from sourcetype1
My final goal is to create a table that lists the event details (time, user, files, results) the last column will be the result that is a little bit more trickier to achieve.
Thanks A Lot Guys!
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

richgalloway

SplunkTrust
01-06-2020
05:45 AM
There probably are a few ways to do that. Here's one.
sourcetype=sourcetype1 OR sourcetype=sourcetype2 | stats values(Field2) by Field1
---
If this reply helps you, Karma would be appreciated.
If this reply helps you, Karma would be appreciated.
