Splunk Search

Consolidation From Different Sources

Cyber_Nerd3
Engager

Hey Everyone!

I'm in need of some help, advice, Ouija board (lol)...whatever can do the trick. I am wanting to know if it is possible to consolidate data from a search that is not generated on Splunk? My supervisor is wanting to receive 1 report instead of 2. Do any of you know if this is even possible? 

Thanks,

Cyber_Nerd3

0 Karma

Cyber_Nerd3
Engager

Ok @ITWhisperer  & @richgalloway  I just got clarification on everything and what he wants is to combine multiple reports located within Splunk into 1 report. I apologize for the misunderstanding on my part, but if either of you could give any input on how to achieve this it would be greatly appreciated.

Thank you!

0 Karma

richgalloway
SplunkTrust
SplunkTrust

We need to know more about the two reports.  How similar are they?  What searches do they use? 

In principle, two reports can be combined, but exactly to do that depends heavily on the reports themselves.  There is no generic answer.

---
If this reply helps you, Karma would be appreciated.
0 Karma

Cyber_Nerd3
Engager

4 are firewall logs which need to be combined into 1 report and the other 2 are just Windows reports. 

I hope this helps, 

Thanks

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Yeah, not really, other than to confirm my "maybe" response.

Search these forums (Google works well) for "combine searches" and you should get a lot of good examples both of how to ask this question and how to solve it.

---
If this reply helps you, Karma would be appreciated.
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Ingest the data or report from the other search into splunk and produce one report from splunk (or tell you supervisor to "man up" and deal with two reports! lol 😀)

Tags (2)

Cyber_Nerd3
Engager

Lol, Thank you so much!

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Please tell us more about the use case.  Where is the other data generated?  Is this other source integrated with Splunk?

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...