Splunk Search

how to compare a field value with all the values in a other column

Rajkumarkbm2
Explorer

Code1 | Descr | Code2 | Descr2 |Level
123 | ABCD | 987 | ZYX1 | level1
456 | EFGH | 678 | ZZZ2 | level1
789 | ACBV | 999 | YYY 3 | level1
987 | ZYX1 | 000 | A123 | level2
987 | ZYX1 | 111 | B123 | level2
678 | ZZZ2 | 222 | J123 | level2
678 | ZZZ2 | 333 | K123 | level2
333 | K123 |011 | K222 | level3

I want to compare Row#1 Code2 is present in Code1. I want to group the values with level 1 to level 3.

Tags (1)
0 Karma

kozanic_FF
Path Finder

Are you able to mock up what you would like your results to look like?

Not really sure what your goal is based on what you have provided so far

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...