Hi. I've been a very basic user of Splunk for a while, but now have a need to perform more advanced searches. I have two different sourcetypes within the same index. Examples of the fields are below. index=vehicles Sourcetype=autos VIN MAKE MODEL Sourcetype=cars SN MANUFACTURER PRODUCT I'd like to search and table VIN, MAKE, MODEL, MANUFACTURER and PRODUCT where - VIN=SN MAKE <> MANUFACTURER OR MODEL<>PRODUCT Basically, where VIN and SN match, if one or both of the other fields don't match, show me. I'm not sure if a join (VIN and SN) statement is the best approach in this case. I've researched and found questions and answers related to searching and comparing multiple sourcetypes. But, I've been unable to find examples that include conditions. Any suggestions you can provide would be greatly appreciated. Thank you!
... View more