Splunk Search

How to compare field3 with common and unique values from field1 and field2?

raju4244
Explorer

Dear All,

I have one question. I have the data like below:

field1:

itema
itemb
itemb
itemc
itemd
iteme
iteme

field2:

itemc
itemd
itemd
iteme

mainfield

itemf
itemc
itemz

I used the search below to get common items and unique items on each fields (field1 and field2).

index=foo source=* |  eval commonfield=coalesce(field1,field2) | stats values(source) as source by commonfield | table commonfield

Now I want to compare the common values from field1 and field2 with mainfield. I want to know what are the common items and unique items on commonfield and main field

All the data is in same index and sourcetype.

Thanks.
Raj

Tags (2)
0 Karma

somesoni2
Revered Legend

Does the main field appears in the same events as field1 and field2?

0 Karma

raju4244
Explorer

no, thats in diiferent source

0 Karma

woodcock
Esteemed Legend

Like this:

index=foo source=* | eval commonfield=coalesce(field1,field2) | stats values(*) as * by commonfield | where commonfield=mainfield

And

index=foo source=* | eval commonfield=coalesce(field1,field2) | stats values(*) as * by commonfield | where commonfield!=mainfield
0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...