Splunk Search

create a table by comparing data from 2 different indexes

arjun_hcl
Explorer

Hi,
I am trying to create a table by comparing data from 2 different indexes & compare certain search terms from one index with matching events from second index

for e.g
index1 may contain a field word and terms error, down, fatal
index2 may contain a field ticket and terms tkt1, tkt2, tkt3

idea is to write duplicate values of tickets against each matiching terms from index1

output would be like
Ticket | word
tkt1 | error
tkt1 | down
tkt1 | fatal
tkt2 | error
tkt2 | down
tkt2 | fatal
.
.
.
etc.

can someone help plz?

0 Karma

niketn
Legend

@arjun_hcl... you would need to provide one key piece of information. Do you have any correlation field between the two indexes?

Consider index and sourcetype in Splunk to be Database and tables. For correlating them we would need to establish a foreign key which is present in both.

If possible please mock up your sample events from both indexes and post them here so that we can help you with the query you need. Do let us know the sourcetype for both indexes also.

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

earlhelms
Path Finder

I'm not sure if I understand the question but this seems to call for a join. Reference: https://docs.splunk.com/Documentation/Splunk/6.5.2/SearchReference/Join

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...