I'm indexing DHCP and Syslog events. To make it for the network administrators a lot easier when they have to know the physical location on a host based on the IP address, I want to make a mapping in Splunk. They both have a MAC Adress (src_mac) so it should be possible to extract the IP address out of the DHCP index.
The search query I made so far does an left join on the dhcp index but it returns a wrong IP address.
Can someone gives me some tips how to make it valid?
Thanks! - Stefan
asked 30 Mar '12, 08:02
Stefan van d...
You should join on a common field for both searches (the outer and the sub-search). Here's an example that would work if both searches provide the src_ip field. If the fields have different names you can either use a FIELDALIAS (in props.conf) or use eval or rename to normalize it.
Additionally I added the usetime modifier for the join command as this probably makes sense for this kind of use-case.
answered 30 Mar '12, 08:26