Splunk newbie here. What I'm trying to do is a pair-wise comparison across all of the values of two different fields, in order to find certain similarities. I already have an initial search which finds the events and values for these two fields, let's call them "foo" and "bar", but the pair-wise comparison aspect is eluding me so far.
Some more info:
More precisely, what I need to go is generate all of the combinations between the values of these two fields, so that I can do the comparison across them. For instance, if "foo" has values of "A" and "B", and "bar" has values of "C" and "D", I would need to compare "A" and "C", "A" and "D", "B" and "C", etc.
So theoretically my search would look something like:
initial_search|pairwise_comparison_stuff|where foo LIKE bar
I feel like this should be possible using streamstats
or something of the like, but any help would be appreciated!
Update: I was able to generate my pair-wise comparison and get things working through map
. However, I did find some weirdness in how map
's search
parameter handles rex
expressions, which took quite a bit of debugging and testing to resolve. I'll probably submit a separate question/issue for that.
Update: I was able to generate my pair-wise comparison and get things working through map
. However, I did find some weirdness in how map
's search
parameter handles rex
expressions, which took quite a bit of debugging and testing to resolve. I'll probably submit a separate question/issue for that.