Splunk Search

How can I take keywords from a field in a search, compare them to another field in the search and the field values that match the keyword, bring them together?

shiv1593
Communicator

Hi All,

I have two data fields, called "Issues" and "Complete issue" which look like this.
alt text

What I want to do is that I want to use keywords like SAP,MCAFEE,AD,WINDOWS,USER*INFORMATION ( I want to use both of these words to get involved in the search), VPN from the field called "Issues", and look for them in the field called "Complete issue" and turn the search results to look like this. In simple words, use the keywords from "Issues", look for them in "Complete issue" and whichever search field contains any of those words, bring them together just like below.
alt text

How can I do this?

Thank you in advance

0 Karma
1 Solution

mdsnmss
SplunkTrust
SplunkTrust

This appears to be about a duplicate of this: https://answers.splunk.com/answers/616151/using-values-of-a-field-compare-them-in-another-fi.html#an.... The method used there can be used to match keywords like this.

View solution in original post

0 Karma

mdsnmss
SplunkTrust
SplunkTrust

This appears to be about a duplicate of this: https://answers.splunk.com/answers/616151/using-values-of-a-field-compare-them-in-another-fi.html#an.... The method used there can be used to match keywords like this.

0 Karma

skoelpin
SplunkTrust
SplunkTrust
0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...