Splunk Search

How to get specified events from 2 indices.

jsven7
Communicator

SITUATION:
- I use indices "A" and "B" to come to answer the same question but for different environments.
- Each index has unique fields names but said fields represent the same data in each index.
- I want a table to answer the same question in one table using both indices.
- I'm starting with SPL similar to this:

(index=A AND  indexA_unqiue_field=x) OR (index=B AND sourcetype=v indexB_unique_field=y)
| rename indexA_unqiue_field AS field
| rename indexB_unique_field AS field
| table _time, field, index

PROBLEM:
- With the above SPL I am failing to answer the same question using the 2 indices. It appears to work fine for index B but "field" does not populate for Index A.

QUESTION:
- How do I get all fields to populate?
- Or how may I achieve the goal?

Labels (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

I think the two renames to the same field name are causing the problem. Try coalesce, instead. It will set 'field' either indexA_unique_field or indexB_unique_field, whichever is present in the event.

(index=A AND  indexA_unqiue_field=x) OR (index=B AND sourcetype=v indexB_unique_field=y)
| eval field = coalesce(indexA_unqiue_field, indexB_unique_field)
| table _time, field, index
---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

I think the two renames to the same field name are causing the problem. Try coalesce, instead. It will set 'field' either indexA_unique_field or indexB_unique_field, whichever is present in the event.

(index=A AND  indexA_unqiue_field=x) OR (index=B AND sourcetype=v indexB_unique_field=y)
| eval field = coalesce(indexA_unqiue_field, indexB_unique_field)
| table _time, field, index
---
If this reply helps you, Karma would be appreciated.

iainsmart
Engager
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to July Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...

Updated Data Type Articles, Anniversary Celebrations, and More on Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

A Prelude to .conf25: Your Guide to Splunk University

Heading to Boston this September for .conf25? Get a jumpstart by arriving a few days early for Splunk ...