Splunk Search

Find a common field with _introspection and _internal or _auit

sairajkiran
Observer

Hi All,

our SVC calculation is in _introspection and and our search name is in _internal and _audit. We need a common filed to map those together so we can tie an SVC (and dollar amount) to a particular search. We tried doing it using the SID but that is not matching. 

Can someone help me out here based on your experiences.

Labels (4)
Tags (1)
0 Karma

Gr0und_Z3r0
Contributor

Hi @sairajkiran 

Try checking the values from the job inspector for your event/search. Not sure if it will fulfil your needs.

The field you can use is search_id -- in _introspection and _audit indexes
For _internal, you'll need to extract this value from job which looks something like this search/search/jobs/1710936732.74/control
so the search_id field value is 1710936732.74 

If the reply helps, a Karma vote would be appreciated.

0 Karma
Get Updates on the Splunk Community!

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

A Guide To Cloud Migration Success

As enterprises’ rapid expansion to the cloud continues, IT leaders are continuously looking for ways to focus ...

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...