Splunk Search

How do i create this kind of relationship of two indexes

DiegoAlba
Explorer

For example
ID field1. ID field2
1 A. 1 X
2 B. 2. Y
1. E. 1. Z
AND I WHAT TO GET THIS
ID field1. field2
1. A. X
1. A. Z
2. B. Y
1. E. X
1. E. Z
Can someone of you help me please

Tags (2)
0 Karma

javiergn
SplunkTrust
SplunkTrust

Sorry I'm a bit confused about your example.

So assuming you have two tables:

  • Table1 (represented by mycsv.csv in the sample below) like this:

    ID,field1
    1,A
    2,B
    1,E

  • Table 2 (represented by mycsv2.csv in the sample below) like this:

    ID,field2
    1,X
    2,Y
    1,Z

The following code:

| inputcsv mycsv.csv 
| join max=0 ID [ | inputcsv mycsv2.csv ]

Will provide the following output:

ID  field1  field2
1   A   X
1   A   Z
2   B   Y
1   E   X
1   E   Z

As per the attached picture.

Is that what you are looking for?
alt text
Thanks,
J

DiegoAlba
Explorer

Hello Javier.

What you understood is exactly what i tried to Say.
Thank you so much!

0 Karma

javiergn
SplunkTrust
SplunkTrust

Hi @DiegoAlba,

If you are happy with the response please don't forget to mark this as answered so that others can benefit from it in future.

Thanks,
J

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...