Splunk Search

How to combine 2 log files that have the same date-time values, but different field names?

anhtrantech
Engager

Hello,

I am basically stuck on this problem that I hope the Splunk community can help me with.

I have 2 files.

Thank you very much.

Tags (3)
0 Karma
1 Solution

masonmorales
Influencer

You can use the join command on the StartTime field. Check out: http://docs.splunk.com/Documentation/Splunk/6.2.2/SearchReference/Join

View solution in original post

masonmorales
Influencer

You can use the join command on the StartTime field. Check out: http://docs.splunk.com/Documentation/Splunk/6.2.2/SearchReference/Join

Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...