Splunk Search

JOIN two table using time as a common key from tow different searches

deepthi5
Path Finder

Hi ,

I have two searches withing same index but different sources and sourcetypes
index=XXX source=XXX |XMLKV |search Category="CDMSP" RI="0" | table _time,Category,F,RI

which gives me time category function and request ID from my app log
and another search

index=XXX source="XXXX" sourcetype=XXXX |table _time,SNMP_Message

Which gives me time and SNMP messages

Now i want to correlate both these searches based on time and display a table so that i can know at a particular time what function,RI ,SNMP Message category are executed
so a complete table based on time

Tags (2)
0 Karma

inventsekar
SplunkTrust
SplunkTrust
index=XXX source=XXX |XMLKV |search Category="CDMSP" RI="0" | [search index=XXX source="XXXX" sourcetype=XXXX |table _time,SNMP_Message] | table _time,Category,F,RI,SNMP_Message

or, please check this one -

 index=XXX source=XXX OR (source="XXXX" sourcetype=XXXX) 
|XMLKV |search Category="CDMSP" RI="0" |table _time,SNMP_Message,Category,F,RI,SNMP_Message
thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...