Splunk Search

Comparing fields when extracting the field from the source

rossparfect
Path Finder

Evening all,

Ive been at this for a couple of days, and although I have built the rest of the search I still cant get my compare and return a success or failure to work.

I have tried Stats, Join, Coalesce, Case ( which works when I manually enter the second field) so heres the challenge,

CSVs lets call them incomingone and ackone123456 and both are from different sourcetypes,

The only way to confirm that the incoming has been successful is to extract the 123456 from the ackone file and then compare it to a field for arguements sake called itshere inside the incomingone one file.

Now if I do stats values and use a MVexpand command I can get a success or failure however I cant display the rest of the fields and need to have way more information on each line.

Now I created my own dummy data and tried it,

index="compare_index" sourcetype="outcomeack" OR sourcetype=outbound | rex field=source "outbound(?\d+)." | eval error = if(outcome == 'REF', "OK", "Problem")

The rex extracts the REF and creates the field however each time I get 3 "problems) note my dummy data is just 3 csvs as the actual environment data I cant post on here and also I wanted to check it wasnt the data.

Also tried a join with a match but still no avail

Anyone have any ideas.

If I use CASE and EVAL with for example 123456 in the eval CASE("itshere=="123456", "success", failure) then that works,

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Data Management Digest – August 2026

MichelleCorpora_1-1788182384472.png Welcome to the August 2026 edition of Data Management Digest! August was a ...

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...