Splunk Search

Does splunk's database support relational search??

keshab
Path Finder

suppose two log file have common field named IPaddress. One log file has username filed with that IPaddress field and another log has kernelno field associated with that IPaddress field. Based on IPaddress common field, can I search between two logs to find username and kernelno??

Tags (1)
0 Karma

Ayn
Legend

Not sure what you mean by relational in this case - if you search for a certain value of the IP address field without any other constraints, all events having that IP address value will show up, whether they belong to the log file with the username or the log file with the kernelno. If you want to cluster them together, you can use the transaction command for creating a combined event (a transaction) from all events containing the same IP address. This transaction will include all the fields from the individual events it contains, so for instance if the fields in your case are called "ip_address", "username" and "kernelno" you could do:

... | transaction ip_address | table ip_address, username, kernelno

This would give you a table containing the username and kernelno for each IP address value. Is this what you want to achieve?

Takajian
Builder

If you want to search two logs with same IPadress, the search syntax is like as bellow.

( sourcetype=logA OR sourcetype=logB ) AND IPaddress=xxx.xxx.xxx.xxx

If you want to correlate two logs, subsearch will be helpful. As for subsearch, please refer to following manual.

http://docs.splunk.com/Documentation/Splunk/4.2.4/User/HowSubsearchesWork

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Data Management Digest – September 2026

    Welcome to the September 2026 edition of Data Management Digest! September brought a fresh wave of ...

Federated Search for CloudWatch Unified Data Store Is Generally Available

As organizations modernize their cloud environments, AWS workloads generate more security, operational, and ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...