Splunk Search

How do I join data from two indexes on a certain field?

sekhar463
Path Finder

Hi all,

i am using a search using internal index but i want to add a field values which is in other index = wineventlog

below is the i am using from internal index 

in the search i want to add a field to table 

 

 

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @sekhar463,

this search cannot run because the Splunk searches run as a pipe, so, if you search for index=_internal at the beginning, you cannot search for another index after because you haven't events from the second index.

You can do something like you described using append but the results of the second search must be less than 50,000 otherwise the subsearch for the second index doesn't give you all the result.

As I said you could use append or (better) you could both the searches in the main search, so you haven't the limit of 50,000 results, something like this:

(index=_internal source=*metrics.log group=tcpin_connections) OR (index=ivz_wintel_wineventlog)
| eval Host=coalesce(hostname, sourceHost), age=(now()-_time)
| stats
   min(age) AS age
   max(_time) AS LastTime
   BY Host
| convert ctime(LastTime) AS "Last Active On"
| eval Status=if(age< 7200,"Running","DOWN")
| rename age AS Age
| eval Age=tostring(Age,"duration")
| sort Status
| table Host Status Age "Last Active On"

Ciao.

Giuseppe

 

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...