Hi,
I have to search for data from two different sourcetypes. There is a common field in both the sourcetypes called id. So When i search using this id it should return the corresponding events from both the sourcetypes. It sould searchin both and return the events if the id exists. Can anyone suggest how to do this? Thanks in advance.
(sourcetype=st_1 OR sourcetype=st_2) id=id_to_search_for
Hi vaishnavi07,
For sure I can suggest how to do this; take a look at this answer here : http://answers.splunk.com/answers/129424/how-to-compare-fields-over-multiple-sourcetypes-without-joi...
It will explain everything to you....
cheers, MuS