Splunk Search

How can I join and group data from 2 different hosts.

jimjohn
Path Finder

How can I join and group data from 2 different hosts.
Say I have HostA , HostB and ID as common field in 2 hosts.
I want to join 2 hosts by Id and group them and do further processing on grouped result.
Ex:
In HostA I have id 10 repeating 1 time and in HostB id 10 is repeating 10 times.
I want to know how may times id 10 occurs in HostA and HostB. How can I achieve this.
Like this different Ids are in 2 hosts. For each ID I want to find the value.

0 Karma

kristian_kolb
Ultra Champion

How long is a piece of string? There are normally a few different ways of solving most problems, but here is one way;

host=hostA OR host=hostB | chart count over ID by host

and another way;

host=hostA OR host=hostB | stats count by ID, host

and yet another way;

host=hostA OR host=hostB | top 20 ID by host

Hope this helps,

K

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...

Introduction to Splunk AI

How are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. Lucky for ...