Splunk Search

how to compare a field value with all the values in a other column

Rajkumarkbm2
Explorer

Code1 | Descr | Code2 | Descr2 |Level
123 | ABCD | 987 | ZYX1 | level1
456 | EFGH | 678 | ZZZ2 | level1
789 | ACBV | 999 | YYY 3 | level1
987 | ZYX1 | 000 | A123 | level2
987 | ZYX1 | 111 | B123 | level2
678 | ZZZ2 | 222 | J123 | level2
678 | ZZZ2 | 333 | K123 | level2
333 | K123 |011 | K222 | level3

I want to compare Row#1 Code2 is present in Code1. I want to group the values with level 1 to level 3.

Tags (1)
0 Karma

kozanic_FF
Path Finder

Are you able to mock up what you would like your results to look like?

Not really sure what your goal is based on what you have provided so far

0 Karma
Get Updates on the Splunk Community!

Splunk Cloud | Empowering Splunk Administrators with Admin Config Service (ACS)

Greetings, Splunk Cloud Admins and Splunk enthusiasts! The Admin Configuration Service (ACS) team is excited ...

Tech Talk | One Log to Rule Them All

One log to rule them all: how you can centralize your troubleshooting with Splunk logs We know how important ...

Splunk Security Content for Threat Detection & Response, Q1 Roundup

Join Principal Threat Researcher, Michael Haag, as he walks through: An introduction to the Splunk Threat ...