Splunk Search

How to create new field with values from a search that uses values of current field?

buttsurfer
Path Finder

I have a search that outputs a table like below

 

         user  |  host  |  app
-------------------------------------

        user1 | host1 | app1

 

I want to add a new field that that finds the Department of the user from another search. So it would look like this 

 

     dep  |  user  |  host  |  app
-------------------------------------

    dep1 |  user1 | host1 | app1

 

 

The second search will have something like this in it so i don't think a join would be sufficient 

 

where match(search,"something\s+user")

 

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @buttsurfer,

in other words: you want to make a join between two searches.

In Splunk there's the "join" command but it must be used only if there isn't any other solution, so you could try this approach:

(index=index1) OR (index=index2)
| stats 
   values(dep) AS dep 
   values(host) AS host 
   values(app) AS app 
   dc(index) AS index_count
   BY user
| where index_count=2
| table dep user host app

Ciao.

Giuseppe

0 Karma

buttsurfer
Path Finder

Hi Giuseppe, thanks for the reply. But how would the second search get the value (user) of the first search's result in order to find its department?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @buttsurfer,

in this way you correlate:

  • user,  host and  app from the first search
  • dep and user from the second search

using user as correlation key

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...