Getting Data In

How to correlate two sourcetypes on a single field?

pjb2160
Path Finder

I wish to correlate two sourcetypes on a single field which I would expect should look something like this:

(sourcetype=type_1 changed_user=*) OR (sourcetype=type_2 users_affected=*) | where changed_user=users_affected | table changed_user, users_affected

Unfortunately this returns no results when I know there are matching results. I have created sample data with "John Smith" appearing in each.

I should also mention that users_affected is likely to have one or more users listed whereas changed_user will only ever have one user listed.

In trying to resolve this I was initially looking for exact matches (on "John Smith") so if anyone knows how I can get this query to first work on an exact match then working to include results where changed_user "exists in" type_2 users_affected that would be much appreciated!

happy to explain further if my intention is not clear!

cheers

Tags (2)
0 Karma

vasanthmss
Motivator

MuS
Legend

I second the second answer 🙂

Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...