Splunk Search

searching for events in a source based on value of another source

kenbaugher
Path Finder

I have two sources that I'd like to combine/join or search on one based on the other.

Source 1 - has two fields  name & date

Source 2  - has several fields including name & date, field1, fields2, field3, etc.

 

I'd like to get the most recent date for a specific name from source 1, and show only the events in source 2 with that name & date

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

You can use the first search as a subsearch to filter the second search - something like this

<search source2> [search <search source1> | stats latest(date) as date by name]
0 Karma

kenbaugher
Path Finder

Thank you, I had to play around with my search a bit, but this overall syntax was the trick

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...