Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How to replace field values received from one search result in one index with second search result in other index by comparing the values?

$
0
0
Index 1 search result:- Provider IP Version Count Provider1 10.10.10.1 1.0 30 Provider1 10.10.10.2 1.0 40 Provider1 10.10.10.3 1.0 100 Provider2 10.10.10.2 1.0 50 Provider2 10.10.10.2 1.0 75 Provider2 10.10.10.6 1.0 81 Provider3 10.10.10.3 1.0 25 Provider3 10.10.10.3 1.0 92 Provider4 10.10.10.4 1.0 20 Index 2 search result:- 10.10.10.110.10.10.210.10.10.310.10.10.410.10.10.510.10.10.110.10.10.210.10.10.310.10.10.610.10.10.710.10.10.8 Could anyone advise me on how to replace the value of all IPs in IP field with second index's Consumer EntityCode, for example, "Ent1" should be replaced with 10.10.10.1 or 10.10.10.2 or 10.10.10.3, "Ent2" should be replaced with 10.10.10.4 or 10.10.10.5, "Ent3" should be replaced with 10.10.10.6 or 7 or 8?

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>