Splunk Search

How can I join and group data from 2 different hosts.

jimjohn
Path Finder

How can I join and group data from 2 different hosts.
Say I have HostA , HostB and ID as common field in 2 hosts.
I want to join 2 hosts by Id and group them and do further processing on grouped result.
Ex:
In HostA I have id 10 repeating 1 time and in HostB id 10 is repeating 10 times.
I want to know how may times id 10 occurs in HostA and HostB. How can I achieve this.
Like this different Ids are in 2 hosts. For each ID I want to find the value.

0 Karma

kristian_kolb
Ultra Champion

How long is a piece of string? There are normally a few different ways of solving most problems, but here is one way;

host=hostA OR host=hostB | chart count over ID by host

and another way;

host=hostA OR host=hostB | stats count by ID, host

and yet another way;

host=hostA OR host=hostB | top 20 ID by host

Hope this helps,

K

Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...