Splunk Search

How can i Search field from two different file source and merge in to a single table ?

JIthesh_Kumar
Explorer

Bellow mentioned table is an example which having same index and sourcetype, but it have a different source. 

I need to search a field from 1st file and the result should be a combination of fields from file 1 and 2.

File 1

 T1_Fld 1 T1_Fld 2Domain T1_Fld 4 T1_Fld 5
AAAxxxgoogle.comyy1bbb
AABxxxFacebook.comyy2bbb
AABxxxGmail.comyy3bbb
AADxxxYahoo.comyy4bbb
AAExxxxxx.comyy5bbb

 

File 2

DomainIP
google.com1.1.1.1
Facebook.com2.2.2.2
Gmail.com3.3.3.3
Yahoo.com4.4.4.4
xxx.com5.5.5.5

 

consider i am running a search where  T1_Fld 1=AAB then the result table form should be like below. 

Output

 T1_Fld 1DomainIP T1_Fld 4
AABFacebook.com2.2.2.2yy2
AABGmail.com3.3.3.3yy3

 

 

Labels (5)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

Use stats to combine them

index=data_set1 OR index=data_set2
| stats values(*) as * by Domain

Here uses values(*) as * to collect all fields from both data sources against their common field Domain.

You can filter then what you do or don't want, e.g. after the above, do  

| where T1_Fld 1="AAB"

 

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...