Splunk Search

correlate value using common field

MrGlass
Explorer

Here is my search in question, the common field is the SessionID

index=eis_lb apm_eis_rdp
|fillnull value="-"
|search UserID!="-"
| rex field=_raw "\/Common\/apm_eis_rdp:ent-eis[:a-zA-Z0-9_.-](?'SessionID'........)"
|search company_info="*"
|rename company_info as "Agency"
| table _time, SessionID, UserID,Full_Name, Agency, HostName, client_ip
| sort - _time

_time                                  SessionID UserID      Full_Name Agency   HostName client_ip
2024-03-22 08:25:29 4f89ae57 Redacted Redacted Redacted Redacted            -


If I remove the Search UserID I can see the matching session ID and the client_ip is present.


_time                               SessionID       UserID    Full_Name    Agency      HostName              client_ip

2024-03-22 14:26:48 4f89ae57     Redacted Redacted    Redacted   Redacted                    -
2024-03-22 14:25:52 4f89ae57 - - - -                                                                                                 Redacted


How can I create a search like above to show the client_ip maching the SessionID

Labels (1)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

Hi

normally you could use e.g. stats to do correlation between events. In your case try e.g.

...
| stats first(_time) as _time values(*) as * by SessionID

This will generate one event by each SessionID with contains other fields as multivalue fields or if values was same in all combined events then normal field.

r. Ismo

View solution in original post

MrGlass
Explorer

Thank You, this worked, the only thing I wish I could see is just the matched lines and get rid of the blank rows.

0 Karma

isoutamo
SplunkTrust
SplunkTrust
You should look e.g where an isnull function. With it you could drop unwanted rows away.
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

normally you could use e.g. stats to do correlation between events. In your case try e.g.

...
| stats first(_time) as _time values(*) as * by SessionID

This will generate one event by each SessionID with contains other fields as multivalue fields or if values was same in all combined events then normal field.

r. Ismo

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...