Splunk Search

SOLVED - How to combine related fields

bleung93
Path Finder

I have this search to display sourcetypes by index.

| metasearch index=* sourcetype=* | stats values(sourcetype) as Sourcetypes by index 

I have this search to show roles with indexes.

| rest /services/authorization/roles/ | rex field=id "https://127.0.0.1/services/authorization/roles/(?<Role>.*)" | table Role srchIndexesAllowed

How would I bring these two together so that the fields tabled are, index, Sourcetypes, and Roles?

Tags (3)
0 Karma
1 Solution

bleung93
Path Finder
| metasearch index=* sourcetype=* | stats values(sourcetype) as Sourcetypes by index | join index [| rest /services/authorization/roles/ | rex field=id "https://127.0.0.1/services/authorization/roles/(?<Role>.*)" | stats values(Role) by srchIndexesAllowed | rename srchIndexesAllowed as index]

View solution in original post

bleung93
Path Finder
| metasearch index=* sourcetype=* | stats values(sourcetype) as Sourcetypes by index | join index [| rest /services/authorization/roles/ | rex field=id "https://127.0.0.1/services/authorization/roles/(?<Role>.*)" | stats values(Role) by srchIndexesAllowed | rename srchIndexesAllowed as index]

isoutamo
SplunkTrust
SplunkTrust
0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...