Dear All,
I have a column named called id in file1.csv and id1 in file2.csv .
File1.csv: File2.csv
ID: ID1
1 1
2 2
3
I have loaded into splunk and assign indexes for two files . I have retrieve the extra value 3 from ID(file1.csv) . Can you please help us in writing the splunk search query. Thanks
Like this:
... | eval comboID=coalesce(id, ID, id1, ID1)
| stats values(comboID)
Thanks for your posting your query. I have the fields in two indexes 1) ID in (index=idx_test) and ID1 in (index=idx_test1). Can you please help me in writing complete query. Thanks
I have tried the above query, its displaying 0 records. Thanks
Did you correct the index names to be the ones you assigned to your files?
index=idx_test OR index=idx_test1
| eval comboID=coalesce(id, ID, id1, ID1)
| stats values(comboID)