Splunk Search

How can I take keywords from a field in a search, compare them to another field in the search and the field values that match the keyword, bring them together?

shiv1593
Communicator

Hi All,

I have two data fields, called "Issues" and "Complete issue" which look like this.
alt text

What I want to do is that I want to use keywords like SAP,MCAFEE,AD,WINDOWS,USER*INFORMATION ( I want to use both of these words to get involved in the search), VPN from the field called "Issues", and look for them in the field called "Complete issue" and turn the search results to look like this. In simple words, use the keywords from "Issues", look for them in "Complete issue" and whichever search field contains any of those words, bring them together just like below.
alt text

How can I do this?

Thank you in advance

0 Karma
1 Solution

mdsnmss
SplunkTrust
SplunkTrust

This appears to be about a duplicate of this: https://answers.splunk.com/answers/616151/using-values-of-a-field-compare-them-in-another-fi.html#an.... The method used there can be used to match keywords like this.

View solution in original post

0 Karma

mdsnmss
SplunkTrust
SplunkTrust

This appears to be about a duplicate of this: https://answers.splunk.com/answers/616151/using-values-of-a-field-compare-them-in-another-fi.html#an.... The method used there can be used to match keywords like this.

0 Karma

skoelpin
SplunkTrust
SplunkTrust
0 Karma
Get Updates on the Splunk Community!

Dashboard Studio Challenge - Learn New Tricks, Showcase Your Skills, and Win Prizes!

Reimagine what you can do with your dashboards. Dashboard Studio is Splunk’s newest dashboard builder to ...

Introducing Edge Processor: Next Gen Data Transformation

We get it - not only can it take a lot of time, money and resources to get data into Splunk, but it also takes ...

Take the 2021 Splunk Career Survey for $50 in Amazon Cash

Help us learn about how Splunk has impacted your career by taking the 2021 Splunk Career Survey. Last year’s ...