Splunk Search

Searching for a string from one sourcetype in another sourcetype which is present as a list

nhvardhan58
Explorer

Hi All,

I have two source type , for example.

1) sourcetype 1
2) sourcetype 2

In sourcetype 1 I have a string which I have queried from a search and I need to search if this string is present in sourcetype2 which is present as a list.

example of the string in sourcetype1.

RHEL-2007:0103

I need to search the above string in Sourcetype2 which is present as a list in dictionary format, example as below.

errata: [ [-]
A
B
C
D
E
F
]

Can somebody please help.

Tags (1)
0 Karma

valiquet
Contributor

index=... sourcetype = 1 OR sourcetype = 2 | stats dc(sourcetype) AS stc by errata | where stc == 2

OR

index=... sourcetype = 2 [ |inputlookup errata |format]

0 Karma

valiquet
Contributor

What is the output of your first search?

0 Karma
Get Updates on the Splunk Community!

Splunk Smartness with Brandon Sternfield | Episode 3

Hello and welcome to another episode of "Splunk Smartness," the interview series where we explore the power of ...

Monitoring Postgres with OpenTelemetry

Behind every business-critical application, you’ll find databases. These behind-the-scenes stores power ...

Mastering Synthetic Browser Testing: Pro Tips to Keep Your Web App Running Smoothly

To start, if you're new to synthetic monitoring, I recommend exploring this synthetic monitoring overview. In ...