Splunk Search

SOLVED - How to combine related fields

Path Finder

I have this search to display sourcetypes by index.

| metasearch index=* sourcetype=* | stats values(sourcetype) as Sourcetypes by index 

I have this search to show roles with indexes.

| rest /services/authorization/roles/ | rex field=id "https://127.0.0.1/services/authorization/roles/(?<Role>.*)" | table Role srchIndexesAllowed

How would I bring these two together so that the fields tabled are, index, Sourcetypes, and Roles?

Tags (3)
0 Karma
1 Solution

Path Finder
| metasearch index=* sourcetype=* | stats values(sourcetype) as Sourcetypes by index | join index [| rest /services/authorization/roles/ | rex field=id "https://127.0.0.1/services/authorization/roles/(?<Role>.*)" | stats values(Role) by srchIndexesAllowed | rename srchIndexesAllowed as index]

View solution in original post

Path Finder
| metasearch index=* sourcetype=* | stats values(sourcetype) as Sourcetypes by index | join index [| rest /services/authorization/roles/ | rex field=id "https://127.0.0.1/services/authorization/roles/(?<Role>.*)" | stats values(Role) by srchIndexesAllowed | rename srchIndexesAllowed as index]

View solution in original post

SplunkTrust
SplunkTrust
0 Karma