Splunk Search

How can I join and group data from 2 different hosts.

jimjohn
Path Finder

How can I join and group data from 2 different hosts.
Say I have HostA , HostB and ID as common field in 2 hosts.
I want to join 2 hosts by Id and group them and do further processing on grouped result.
Ex:
In HostA I have id 10 repeating 1 time and in HostB id 10 is repeating 10 times.
I want to know how may times id 10 occurs in HostA and HostB. How can I achieve this.
Like this different Ids are in 2 hosts. For each ID I want to find the value.

0 Karma

kristian_kolb
Ultra Champion

How long is a piece of string? There are normally a few different ways of solving most problems, but here is one way;

host=hostA OR host=hostB | chart count over ID by host

and another way;

host=hostA OR host=hostB | stats count by ID, host

and yet another way;

host=hostA OR host=hostB | top 20 ID by host

Hope this helps,

K

Get Updates on the Splunk Community!

Earn a $35 Gift Card for Answering our Splunk Admins & App Developer Survey

Survey for Splunk Admins and App Developers is open now! | Earn a $35 gift card!      Hello there,  Splunk ...

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...