Splunk Search

Associating fields across events

999chris
New Member

Hi All,

I was hoping someone could answer my query:

I have the following:

index=ateme status=* | eval progress=if(status=="complete",100,progress) | stats latest(status) as Status, latest(progress) as Progress by jobId

Which creates a table I need. However the "jobId" field needs to be cross referenced with another field in a different event entry which would give me a filename and I would like to replace the jobId column with the filename associated with that jobId.

Does that make sense?

0 Karma

sundareshr
Legend

If the event that has the Filename also has the jobid, you can try this. If it doesn't you have to provide some samples

index=ateme status=* | eventstats values(filename) as filename by jobId | eval progress=if(status=="complete",100,progress) | stats latest(status) as Status, latest(progress) as Progress by filename 
0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...