Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Query joining 3 sourcetypes

$
0
0
I am trying to create a query that combines results from 3 sources, one of which is a lookup table. Any help would be appreciated. (sourcetype="sourcetypeA OR sourcetype="sourcetypeB" ) fieldinsourcetypeAndB=* | fields [all fields in A and B] |stats values(*) as * by fieldinsourcetypeAndB |appendcols [| inputlookup sourcetypeC.csv | fields fieldinA fieldinC]

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>