Splunk Search

Using another index and replace the missing values in the current index data.


I have a index say index1 having Air Details and ServerName of which some Air is missing for some serverNames.

I have another index say index2 in this index i am getting the Air details that are missing in index1.

Want to use index2 Air where i dont have values in index 1.

Labels (3)
0 Karma


There needs to be a connection between index1 and index2 so Splunk knows which ServerName belongs to which Air Details.  Once you have that you can join the two indexes something like this

(index=index1 OR index=index2)
| stats values(*) as * by ServerName
If this reply helps you, an upvote would be appreciated.
0 Karma
*NEW* Splunk Love Promo!
Snag a $25 Visa Gift Card for Giving Your Review!

It's another Splunk Love Special! For a limited time, you can review one of our select Splunk products through Gartner Peer Insights and receive a $25 Visa gift card!


Or Learn More in Our Blog >>