Splunk Search

How to associate related fields in different log files to form a statistic table

akdake
Explorer

I have two different data sources:

log 1 include field 'a' and 'b'
log 2 include field 'b'and 'c'

Now i want to create a statistic table including field 'a','b','c' how do i do this? pls. help me Thanks!

Tags (3)
0 Karma

fox
Path Finder

search log1 | join type=left b [search log2] | table a b c

fox
Path Finder

a simple join query posted into a summery index for quick post processing...?

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...