Splunk Search

Merge tables by aligning fields with same value

Thuan
Explorer

Hello,

I have two tables listed below. The small table is a subset of the large table.

Large_table Small_table

large_source_field small_source_field
Account_Domain registry_key_name
Account_Name registry_path

AddressFamily registry_type
registry_key_name

registry_path

registry_type

I like to merge the two tables into a single one (see below) with entries with the same value on the same row

After_merging_table

large_source_field small_source_field
Account_Domain

Account_Name

AddressFamily

registry_key_name registry_key_name
registry_path registry_path
registry_type registry_type

Any help will be much appreciated

Tags (2)
0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...