Splunk Search

How to combine 2 log files that have the same date-time values, but different field names?

anhtrantech
Engager

Hello,

I am basically stuck on this problem that I hope the Splunk community can help me with.

I have 2 files.

Thank you very much.

Tags (3)
0 Karma
1 Solution

masonmorales
Influencer

You can use the join command on the StartTime field. Check out: http://docs.splunk.com/Documentation/Splunk/6.2.2/SearchReference/Join

View solution in original post

masonmorales
Influencer

You can use the join command on the StartTime field. Check out: http://docs.splunk.com/Documentation/Splunk/6.2.2/SearchReference/Join

Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...