Splunk Search

How to build a datamodel like this ?

szabados
Communicator

My data consists of pairs of files, lets call them file_A_1...file_A_n, and file_B_1...file_B_n, where file_A_1 is connected with file_B_1.
The pairs are always ingested at the same time together. The first step I need in my datamodel is to join the corresponding pairs, like
source=file_A_1 join type=outer myIDField [ search source=file_B_1 ]. How can I achieve this dynamically, with every pair of file?

Tags (3)
0 Karma

Jeremiah
Motivator

If myIDField is unique across all files, do you really need to join the two files together?

source=file_A* OR source=file_B* | stats values(*) AS * by myIDField

If the myIDField value is not unique, you could also extract the id number from the file.

source=file_A* OR source=file_B* | rex field=source "_(?<file_id>\d+)" | stats values(*) AS * by myIDField, file_id

jplumsdaine22
Influencer

Here is a handy chart on when to use the various aggregators

http://docs.splunk.com/Documentation/Splunk/6.3.2/Search/Abouteventcorrelation

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In January, the Splunk Threat Research Team had one release of new security content via the Splunk ES Content ...

Expert Tips from Splunk Professional Services, Ensuring Compliance, and More New ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Observability Release Update: AI Assistant, AppD + Observability Cloud Integrations & ...

This month’s releases across the Splunk Observability portfolio deliver earlier detection and faster ...