Splunk Search

How to compare field3 with common and unique values from field1 and field2?

raju4244
Explorer

Dear All,

I have one question. I have the data like below:

field1:

itema
itemb
itemb
itemc
itemd
iteme
iteme

field2:

itemc
itemd
itemd
iteme

mainfield

itemf
itemc
itemz

I used the search below to get common items and unique items on each fields (field1 and field2).

index=foo source=* |  eval commonfield=coalesce(field1,field2) | stats values(source) as source by commonfield | table commonfield

Now I want to compare the common values from field1 and field2 with mainfield. I want to know what are the common items and unique items on commonfield and main field

All the data is in same index and sourcetype.

Thanks.
Raj

Tags (2)
0 Karma

somesoni2
Revered Legend

Does the main field appears in the same events as field1 and field2?

0 Karma

raju4244
Explorer

no, thats in diiferent source

0 Karma

woodcock
Esteemed Legend

Like this:

index=foo source=* | eval commonfield=coalesce(field1,field2) | stats values(*) as * by commonfield | where commonfield=mainfield

And

index=foo source=* | eval commonfield=coalesce(field1,field2) | stats values(*) as * by commonfield | where commonfield!=mainfield
0 Karma
Get Updates on the Splunk Community!

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...

Observability protocols to know about

Observability protocols define the specifications or formats for collecting, encoding, transporting, and ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...