Splunk Search

Join matching field of a Sub-Search

epw0rrell
Explorer

Hello, I currently have a search over index_A that runs a sub-search from index_B looking to match a field (field_B) from index_B to any log within index_A.  The search works great but the only frustration is not knowing what field value that field_B held as all of the tabled results come from index_A.  Is there a way I can join that matched field_B to the results at the end of the search?  Here is my current search and thanks for anyone that has the time to help me with this!

index=index_A [search index=index_B | fields field_B | rename field_B as query] 
| table field_A field_A1 field_A2 field_A3

 

Labels (4)
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...

Announcing the 1st Round Champion’s Tribute Winners of the Great Resilience Quest

We are happy to announce the 20 lucky questers who are selected to be the first round of Champion's Tribute ...

We’ve Got Education Validation!

Are you feeling it? All the career-boosting benefits of up-skilling with Splunk? It’s not just a feeling, it's ...