Splunk Search

How do you combine data from two source types based on common values?

dminev1
Explorer

Hi there,

I have a question regarding source types. I have 2 source types "A" and "B". "A" has a field called "aaa" and "B" has field call "bbb". These two fields share the same value ( example: aaa=123, bbb=123) but the field name is different. I want to combine the two source types based on the fields with the same value(the value will change dynamically so I can't hardcode it) and extract data from both source types.

Is it possible and if it is, how would I approach this?

I tried something like this:

index=???  host=??? (sourcetype=A OR sourcetype=B) 
| rename aaa as bbb
| rex field=_raw "ClientId=(?\d+)"
| stats values(cID) as ID by bbb
| eval Duration = round(Duration,3)
| tab
0 Karma
1 Solution

somesoni2
Revered Legend

Try something like this

index=???  host=??? (sourcetype=A OR sourcetype=B) 
 | eval commonfield=coalesce(aaa,bbb)
 | rex field=_raw "ClientId=(?<cID>\d+)"
 | stats values(cID) as ID values(Duration) as Duration by commonfield
 | eval Duration = round(Duration,3)

View solution in original post

0 Karma

somesoni2
Revered Legend

Try something like this

index=???  host=??? (sourcetype=A OR sourcetype=B) 
 | eval commonfield=coalesce(aaa,bbb)
 | rex field=_raw "ClientId=(?<cID>\d+)"
 | stats values(cID) as ID values(Duration) as Duration by commonfield
 | eval Duration = round(Duration,3)
0 Karma

dminev1
Explorer

It worked. Thank you for the quick response.

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...