Splunk Search

How do i create this kind of relationship of two indexes

DiegoAlba
Explorer

For example
ID field1. ID field2
1 A. 1 X
2 B. 2. Y
1. E. 1. Z
AND I WHAT TO GET THIS
ID field1. field2
1. A. X
1. A. Z
2. B. Y
1. E. X
1. E. Z
Can someone of you help me please

Tags (2)
0 Karma

javiergn
Super Champion

Sorry I'm a bit confused about your example.

So assuming you have two tables:

  • Table1 (represented by mycsv.csv in the sample below) like this:

    ID,field1
    1,A
    2,B
    1,E

  • Table 2 (represented by mycsv2.csv in the sample below) like this:

    ID,field2
    1,X
    2,Y
    1,Z

The following code:

| inputcsv mycsv.csv 
| join max=0 ID [ | inputcsv mycsv2.csv ]

Will provide the following output:

ID  field1  field2
1   A   X
1   A   Z
2   B   Y
1   E   X
1   E   Z

As per the attached picture.

Is that what you are looking for?
alt text
Thanks,
J

DiegoAlba
Explorer

Hello Javier.

What you understood is exactly what i tried to Say.
Thank you so much!

0 Karma

javiergn
Super Champion

Hi @DiegoAlba,

If you are happy with the response please don't forget to mark this as answered so that others can benefit from it in future.

Thanks,
J

0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...