Hello Splunker, I have a below scenario where i am struggling to come up with search query, and would like to ask your expert advise to achieve the same. I have two database tables A and B and i have ingested them in two different sources in my splunk instance. Table A has data related to Job which basically has fields like JobID, JobName, StartTime, EndTime Table B has data related to Job execution details like JobID, AgentName, JobType, JobDate,JobEndHour Certain Jobs (Table A) takes longer time to finish and to find out the details in terms of whats was going on during the time Job (Which is taking longer) was running can be found from Table B. To find data from Table B, First we need to find out which Agent (AgentName) was handling the job (using JobID, StartTime, EndTime) and once we have Agent details, we have to search again in Table B that during those hours (StartTime, EndTime) what other Jobs were handled including Job in question by the Agent. Both tables has JobID as common field. Any help or pointers are highly appreciated. Thanks.
... View more