Splunk Search

Joining two fields with different names

JoeSco27
Communicator

I am trying to join two fields from different indexers, they both return IP Addresses but are under different field names.

Tags (1)
0 Karma

yannK
Splunk Employee
Splunk Employee

Use an eval to create the missing field in one of the searches.

example :
source=fileA | JOIN fieldA [ search source=fileB | eval fieldA=fieldB ]

Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...