Splunk Search

What is the most efficient way to reconcile the data from 2 indexes and create a report?

iamsplunker
Communicator

I wanted to reconcile the data from 2 indexes say index=A and index=B both indexes have some common fileds like field1,field2,field3,field4,field5

at the end I wanted to compare the data from index A and index B side by side with time span of 1s.

The report should display _time index1 index2 source field1 field2 field3 field4 field5 and difference between the 2 indexes eventcount or any other.

Tags (2)
0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi, 

1) is this an one time report task or you want this report to be run weekly/monthly, etc

if you want to run this report weekly/monthly, then, summary indexing (link), report acceleration(link) will help you very good. 

2) how big the two indexes are.. 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

iamsplunker
Communicator

@inventsekar Do you have any examples/sample search to share for my requirement.

0 Karma

iamsplunker
Communicator

hi @inventsekar , Thanks for your response. For now it's a one time report. I'm looking for a sample search to accomplish this.

we have about ~ 3-5K events per day

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...