Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Build a table with information from various sourcetype

$
0
0
I have two different logsource, ProxyLogs: Contains "ipaddress" and "username" WebLogs: Conatains "IP_address" and whole other stuff like UserAgent, Time, Branch,HostName,loginname I have a query that is giving me following things which i want TIme, IP, hostname, UA, loginname, Branch But my requirement is to Lookup the individual "ipaddress" from ProxyLogs in the Weblogs and find the matching username (i.e who that IP belongs to) Time, IP, hostname, UA, loginname, Branch, username I have this so far: sourcetype=WebLogs (**other- logic**)| stats count by Time,IP_address,HostName,UserAgent,loginname,Branch| rename IP_address as IP | rename UserAgent as UA | join IP type=outer [search sourcetype=WebLogs |fields username ipaddress] But this result in random user every i run the search. Any help will be really appreciated.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>