- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How do I join different events on an ID with different source types?
nikosattlermhp
Engager
10-24-2018
12:29 AM
Hello everybody,
I have many messages with two different source types and an ID and a information field. For every ID, there is one message from source 1 and one from source 2. I need to display to every ID the information field of both source types:
Example:
ID | Source 1 | Source 2 |
1 | info field from source 1 | info field from source 2 |
2 |info field from source 2 | null |
If there is no second event to an ID from the other source, "null" should be displayed.
How can I perform this join/combination?
My try:
index=myindex source1 | table id, infofield1 | join type=outer [search index=myindex source2 |table id, infofield2]
Thank you in advance!
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

richgalloway

SplunkTrust
10-24-2018
05:47 AM
Here's something to try.
index=myindex (source1 OR source2) | stats values(infofield1) as infofield1 values(infofield2) as infofield2 by id | fillnull infofield2
---
If this reply helps you, Karma would be appreciated.
If this reply helps you, Karma would be appreciated.
