Splunk Search

How can I take keywords from a field in a search, compare them to another field in the search and the field values that match the keyword, bring them together?

shiv1593
Communicator

Hi All,

I have two data fields, called "Issues" and "Complete issue" which look like this.
alt text

What I want to do is that I want to use keywords like SAP,MCAFEE,AD,WINDOWS,USER*INFORMATION ( I want to use both of these words to get involved in the search), VPN from the field called "Issues", and look for them in the field called "Complete issue" and turn the search results to look like this. In simple words, use the keywords from "Issues", look for them in "Complete issue" and whichever search field contains any of those words, bring them together just like below.
alt text

How can I do this?

Thank you in advance

0 Karma
1 Solution

mdsnmss
SplunkTrust
SplunkTrust

This appears to be about a duplicate of this: https://answers.splunk.com/answers/616151/using-values-of-a-field-compare-them-in-another-fi.html#an.... The method used there can be used to match keywords like this.

View solution in original post

0 Karma

mdsnmss
SplunkTrust
SplunkTrust

This appears to be about a duplicate of this: https://answers.splunk.com/answers/616151/using-values-of-a-field-compare-them-in-another-fi.html#an.... The method used there can be used to match keywords like this.

View solution in original post

0 Karma

skoelpin
SplunkTrust
SplunkTrust
0 Karma
.conf21 Now Fully Virtual!
Register for FREE Today!

We've made .conf21 totally virtual and totally FREE! Our completely online experience will run from 10/19 through 10/20 with some additional events, too!