Splunk Search

How can I take keywords from a field in a search, compare them to another field in the search and the field values that match the keyword, bring them together?

Communicator

Hi All,

I have two data fields, called "Issues" and "Complete issue" which look like this.
alt text

What I want to do is that I want to use keywords like SAP,MCAFEE,AD,WINDOWS,USER*INFORMATION ( I want to use both of these words to get involved in the search), VPN from the field called "Issues", and look for them in the field called "Complete issue" and turn the search results to look like this. In simple words, use the keywords from "Issues", look for them in "Complete issue" and whichever search field contains any of those words, bring them together just like below.
alt text

How can I do this?

Thank you in advance

0 Karma
1 Solution

SplunkTrust
SplunkTrust

This appears to be about a duplicate of this: https://answers.splunk.com/answers/616151/using-values-of-a-field-compare-them-in-another-fi.html#an.... The method used there can be used to match keywords like this.

View solution in original post

0 Karma

SplunkTrust
SplunkTrust

This appears to be about a duplicate of this: https://answers.splunk.com/answers/616151/using-values-of-a-field-compare-them-in-another-fi.html#an.... The method used there can be used to match keywords like this.

View solution in original post

0 Karma

SplunkTrust
SplunkTrust
0 Karma