Two different sources returning data in the below format.
Source 1 - Determines the time range for a given date based on the execution of a Job, which logically concludes the End of Day in Application.
Source 2 – Events generated in real time for various use cases in the application. EventID1 is generated as part of the Job in Source1.
Source 1
DATE
Start Time
End Time
Day 3
2023-09-12 01:12:12.123
2023-09-13 01:13:13.123
Day 2
2023-09-11 01:11:11.123
2023-09-12 01:12:12.123
Day 1
2023-09-10 01:10:10.123
2023-09-11 01:11:11.123
Source 2
Event type
Time
Others
EventID2
2023-09-11 01:20:20.123
EventID1
2023-09-11 01:11:11.123
EventID9
2023-09-10 01:20:30.123
EventID3
2023-09-10 01:20:10.123
EventID5
2023-09-10 01:10:20.123
EventID1
2023-09-10 01:10:10.123
There are no common fields available to join the two sources other than the time at which the job is executed and at which the EventID1 is generated.
Expectation is to logically group the events based on Date and derive the stats for each day.
I'm new to Splunk and i would really appreciate if you guys can provide suggestions on how to handle this one.
Expected Result
Date
Events
Count
Day 1
EventID1 EventID2 EventID3 - - - EventID9
1 15 10 - - 8
Day 2
EventID1 EventID2 - - - EventID9 EventID11
1 2 - - 18 6
... View more