Splunk Search

How to use value of one search and get more details about the value from another search

maggiesa
New Member

Example:
Fetch VPN user details from one search and use the username to get details like email addresses from another search.

index=## host= ## sourcetype="##" source="#.log" eventtype=# parent session started
|  table user host src_ip group

This lists details like:

user host src_ip group
bxxxx.gwwww x.x.x.x x.x.x.x Finance

I would like to add more details to the table like email address of the person and location which i can get from
index=@@ sourcetype=@@

   Company: xyz 
   Employee_ID: aaa
   Full_Legal_Name: Mr.ttt ccc 
   Future_Termination_TF: 0 
   Location: ddd
   Primary_Work_Email:  bxxxx.gwwww@xyz.com

How do I take the user details from the first search like ( bxxxx.gwwww) and match it to the second search to get the email address and other info?

The only partially matching value between 2 searches is the users name , there are no field matches between both searches.

0 Karma

jinseong
Path Finder

Hello.

I will present a total of two methods.

First, the values ​​from the first search are made into lookup files. After that, through lookup command, it connects to the second search and composes it into a table.

The second append or join command creates a matching part of different searches and organizes them into a table.

For more information on the search, please see the search reference manual or ask a question again.

Thank you.

0 Karma
Get Updates on the Splunk Community!

New Case Study: How LSU’s Student-Powered SOCs and Splunk Are Shaping the Future of ...

Louisiana State University (LSU) is shaping the next generation of cybersecurity professionals through its ...

Splunk and Fraud

Join us on November 13 at 11 am PT / 2 pm ET!Join us for an insightful webinar where we delve into the ...

Build Your First SPL2 App!

Watch the recording now!.Do you want to SPL™, too? SPL2, Splunk's next-generation data search and preparation ...