Splunk Search

Two fields (same value), fill in third field

rocarril
Engager

My dataset has three fields from two different data sources. Two fields are identical (hostnames with different field names). One dataset has a third field that I would like to fill in. Example:

sourcetype . hostname1 computer1 . domain
source1 . host1 . NT1
source1 . host2 NT2
source2 host1
source2 host2

Want to it to be:

sourcetype . hostname1 computer1 . domain
source1 . host1 . host1 NT1
source1 . host2 host2 NT2
source2 host1 host1 NT1
source2 host2 host2 . NT2

Tags (1)
0 Karma

Kwip
Contributor

| eval Domain=case(
hostname1="host1" AND computername1="host1", "NT1",
hostname1="host2" AND computername1="host2", "NT2")

Same can achieve via lookup if you have large no of values to be created.

0 Karma

micahkemp
Champion

How are the values NT1 and NT2 determined for the last two events in your example output?

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...