Splunk Search

How do you combine data from two source types based on common values?

dminev1
Explorer

Hi there,

I have a question regarding source types. I have 2 source types "A" and "B". "A" has a field called "aaa" and "B" has field call "bbb". These two fields share the same value ( example: aaa=123, bbb=123) but the field name is different. I want to combine the two source types based on the fields with the same value(the value will change dynamically so I can't hardcode it) and extract data from both source types.

Is it possible and if it is, how would I approach this?

I tried something like this:

index=???  host=??? (sourcetype=A OR sourcetype=B) 
| rename aaa as bbb
| rex field=_raw "ClientId=(?\d+)"
| stats values(cID) as ID by bbb
| eval Duration = round(Duration,3)
| tab
0 Karma
1 Solution

somesoni2
Revered Legend

Try something like this

index=???  host=??? (sourcetype=A OR sourcetype=B) 
 | eval commonfield=coalesce(aaa,bbb)
 | rex field=_raw "ClientId=(?<cID>\d+)"
 | stats values(cID) as ID values(Duration) as Duration by commonfield
 | eval Duration = round(Duration,3)

View solution in original post

0 Karma

somesoni2
Revered Legend

Try something like this

index=???  host=??? (sourcetype=A OR sourcetype=B) 
 | eval commonfield=coalesce(aaa,bbb)
 | rex field=_raw "ClientId=(?<cID>\d+)"
 | stats values(cID) as ID values(Duration) as Duration by commonfield
 | eval Duration = round(Duration,3)
0 Karma

dminev1
Explorer

It worked. Thank you for the quick response.

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...