Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How to search for Matching fields using 2 different host with Same sourcetype

$
0
0
I'm looking to find matching field (lets call this field action) from 2 different host with the same sourcetype. example Sourcetype=pan host=1 and host=2 I'm looking to create a ta table that would show the matching field for field action (I only want the matching field to generate result) so if host 1 has action=allowed and host 2 has action=allowed. I want to create a table that would include the time, action, src, dest.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>