Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How do you combine data from two source types based on common values?

$
0
0
Hi there, I have a question regarding source types. I have 2 source types "A" and "B". "A" has a field called "aaa" and "B" has field call "bbb". These two fields share the same value ( example: aaa=123, bbb=123) but the field name is different. I want to combine the two source types based on the fields with the same value(the value will change dynamically so I can't hardcode it) and extract data from both source types. Is it possible and if it is, how would I approach this? I tried something like this: index=??? host=??? (sourcetype=A OR sourcetype=B) | rename aaa as bbb | rex field=_raw "ClientId=(?\d+)" | stats values(cID) as ID by bbb | eval Duration = round(Duration,3) | tab

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>