Splunk Search

Searching for a string from one sourcetype in another sourcetype which is present as a list

nhvardhan58
Explorer

Hi All,

I have two source type , for example.

1) sourcetype 1
2) sourcetype 2

In sourcetype 1 I have a string which I have queried from a search and I need to search if this string is present in sourcetype2 which is present as a list.

example of the string in sourcetype1.

RHEL-2007:0103

I need to search the above string in Sourcetype2 which is present as a list in dictionary format, example as below.

errata: [ [-]
A
B
C
D
E
F
]

Can somebody please help.

Tags (1)
0 Karma

valiquet
Contributor

index=... sourcetype = 1 OR sourcetype = 2 | stats dc(sourcetype) AS stc by errata | where stc == 2

OR

index=... sourcetype = 2 [ |inputlookup errata |format]

0 Karma

valiquet
Contributor

What is the output of your first search?

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...