Hi Splunk Experts,
I have 2 files
File1:
Filer_Name Dept Volume_Name Vol_Total Vol_Used
Abcd Vol1 100 50
File 2:
Filer_Name Dept Volume_Name Vol_Total Vol_Used
Abcd IT Vol1
File 1 is generated by storage monitoring script and file 2 is maintained manually with Dept name.
What I want to do is, I want to concatenate “ Filer_Name ” and “ Volume_Name ” in both files and based on the value lookup for Dept in File2.
How can do this in Splunk?
I got to the point of concatenating the fields in file 1, but not sure how to do lookup based in concatenated value from file 2.
I have indexed both files in splunk.
Can anyone tell me if this is possible.
Thanks for your help,
Muru
... View more