Hola Splunkers !!
i want to search in two indexes with one common values in between, for exapmle:
index=Exchange_server has the following fields: sender, subject
index=EmailProxy has the following fields: src_ip, sender
where the sender value is the same in the two indexes
i want the output to conclude: src_ip, SenderMail, Subject
here's my search:
index=Exchange_server OR index=EmailProxy | table src_ip message_subjec sender
but unfortunately i got many blank fields, please help me with it.
Thanks^_^
try this
index=msexchange OR index=cisco_esa | stats values(message_subject) as message_subject values(sender) as sender by src_ip