Splunk Search

Find a common field with _introspection and _internal or _auit

sairajkiran
Observer

Hi All,

our SVC calculation is in _introspection and and our search name is in _internal and _audit. We need a common filed to map those together so we can tie an SVC (and dollar amount) to a particular search. We tried doing it using the SID but that is not matching. 

Can someone help me out here based on your experiences.

Labels (4)
Tags (1)
0 Karma

Gr0und_Z3r0
Contributor

Hi @sairajkiran 

Try checking the values from the job inspector for your event/search. Not sure if it will fulfil your needs.

The field you can use is search_id -- in _introspection and _audit indexes
For _internal, you'll need to extract this value from job which looks something like this search/search/jobs/1710936732.74/control
so the search_id field value is 1710936732.74 

If the reply helps, a Karma vote would be appreciated.

0 Karma
Get Updates on the Splunk Community!

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...