Hi,
I am new to Splunk and am stuck at the this problem. To elaborate:
I have attached example of datasets and the desired result table that I am working with here. Datasets that I am using are KVStore lookups.
But basically I am trying to connect dataset 1 to dataset 2 bringing over attributes (Flag A,B & C) based on condition.
Condition is applied to column "Application Name" and there is many to one mapping which is confusing me.
Any help is greatly appreciated !
(PS: Key is to have value of Flag= True in the output if it is true for any of the application mapped to that device name)
- Rohan ![alt text][1]
[1]: /storage/temp/274901-2019-10-12-14-08-10.jpg
↧