I want to join with search results and correlate to the specific event. Trying _cd
field, but it doesn't appear to return any values.
index=main * | join _cd [search *]
I was expecting to see some bucket and address values?
earliest="-1s" * | rex field=_cd "(?<bucket>d+):(?<address>d+)"
hi esumerfd,
try following these link below:
http://answers.splunk.com/answers/49/does-each-splunk-event-have-a-unique-identifier.html
http://answers.splunk.com/answers/10256/get-bucket-ids-corresponding-to-events.html