Splunk Search

compare two fields value for equality in two different indexes

simin67rose
New Member

HI
I want to know why this code is not working
index="malecious_url" OR index="surikata" |fields http2,http | where(http==http2)

I want to compare them and show which thing is similar in 2 fields that I created in 2 different indexes and sourcetypes

Tags (1)
0 Karma

starcher
Influencer

== is equal. Similar is not the same statement. So, if the fields do not match exactly you will get no results. try a table http, http2 on the end and skim the results to see how they look compared to each other.

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...