Splunk Search

How to join different fields together?

jhilton90
Path Finder

I have an index called index=advanced_hunting and in this index there is a field called category, where there are several categories like 

AdvancedHunting-DeviceFileEvents

AdvancedHunting-DeviceNetworkEvents etc

I'm trying to look into the AdvancedHunting-DeviceFileEvents category to look at what files have been deleted, but the logs in that specific category don't feature the properties.AccountName i.e. the person, it does however, have a filed called properties.DeviceName.

However, the category of AdvancedHunting-DeviceLogonEvents does have a field called properties.AccountName, as well as properties.DeviceName.

So I was wondering if it's possible to connect the properties.AccountName and properties.DeviceName together so I can see who has deleted something

Labels (3)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @jhilton90,

in Splunk it's possible to join two fields using eval command:

| eval new_field='properties.AccountName'."-".'properties.DeviceName'

there could be an issue related to the dot in the field name, so please try this:

| rename properties.AccountName AS AccountName properties.DeviceName AS DeviceName
| eval new_field=AccountName."-".DeviceName

Ciao.

Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @jhilton90,

in Splunk it's possible to join two fields using eval command:

| eval new_field='properties.AccountName'."-".'properties.DeviceName'

there could be an issue related to the dot in the field name, so please try this:

| rename properties.AccountName AS AccountName properties.DeviceName AS DeviceName
| eval new_field=AccountName."-".DeviceName

Ciao.

Giuseppe

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @jhilton90 ,

good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

❄️ Celebrate the season with our December lineup of Community Office Hours, Tech Talks, and Webinars! ...

Splunk and Fraud

Watch Now!Watch an insightful webinar where we delve into the innovative approaches to solving fraud using the ...

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...