Hai everyone,
I'm still a newbie to using Splunk. I want to ask about selecting and joining fields in 2 sources.
Example:
source 1: S1
fields: A1, B1, C1
source 2: S2
fields: A1, A2, B2
I want to select A1, B1, C1, A2, B2 and join A1 in source 1 and source 2.
How would I write this search in Splunk??
please, help me
thanks
... View more