Hi,
How do I search in two indexes? I am looking for the IP address in both the indexes at that same point of time and correlate them.
One index is firewall and other index is Microsoft ATA.
Hi @ajayrejin ,
You can join
command if if you have common field in both the indexes.
you can follow this doc for better reference.
https://docs.splunk.com/Documentation/Splunk/7.2.4/SearchReference/Join
or you can use transaction
command
https://docs.splunk.com/Documentation/Splunk/7.2.4/SearchReference/Transaction
this might help you!
Hi,
There is no common field in both the indexes.
Like this
(index=A OR index=B)
Hi,
Okay.. That query would check either in A or B right.
What i am looking for here is, the IP is in both indexes and that IP is present in both indexes at the same time. I need to correlate them..
Ex: IP in index 1 is seen @ 12 PM, then same IP is also seen @ 12PM in index 2. How do i check this? If the IPs have seen @ same time.
Yes correct, this will search both indexes. If you want to coorelate between both indexes, you can use the search below to get you started.
You will need to replace your index name and srcip
with the field-name of your IP value.
(index=A OR index=B)
| stats count earliest(_time) as _time by srcip
| where count >=2
Thank you for the query. I tried that query, it gives me all the IPs from both the indexes. I wanted the common IP between the indexes