<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Include two index events without using JOIN command in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-include-two-index-events-without-using-JOIN-command/m-p/616318#M14135</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244498"&gt;@super_saiyan&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please try this?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=IDX1 OR index=IDX2 | stats values(User_IP) as User_IP,values(Action) as Action, values(Comments) as Comments by ID&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Change the index name and field name as per your requirement.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;KV&lt;/P&gt;&lt;P&gt;AKA- GOKU&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 07 Oct 2022 14:08:23 GMT</pubDate>
    <dc:creator>kamlesh_vaghela</dc:creator>
    <dc:date>2022-10-07T14:08:23Z</dc:date>
    <item>
      <title>How to include two index events without using JOIN command?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-include-two-index-events-without-using-JOIN-command/m-p/616316#M14134</link>
      <description>&lt;P&gt;Hi Splunkers,&lt;/P&gt;&lt;P&gt;There is one field is common in 2 indexes. Using that field how can i co-relate and make a table out of it without using &lt;STRONG&gt;JOIN, Append &amp;amp; Appendpipe&lt;/STRONG&gt; command ? Because those command will take a lot of time and&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please refer to the below pictures&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks &amp;amp; regards&lt;/P&gt;</description>
      <pubDate>Fri, 07 Oct 2022 14:45:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-include-two-index-events-without-using-JOIN-command/m-p/616316#M14134</guid>
      <dc:creator>super_saiyan</dc:creator>
      <dc:date>2022-10-07T14:45:39Z</dc:date>
    </item>
    <item>
      <title>Re: Include two index events without using JOIN command</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-include-two-index-events-without-using-JOIN-command/m-p/616318#M14135</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244498"&gt;@super_saiyan&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please try this?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=IDX1 OR index=IDX2 | stats values(User_IP) as User_IP,values(Action) as Action, values(Comments) as Comments by ID&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Change the index name and field name as per your requirement.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;KV&lt;/P&gt;&lt;P&gt;AKA- GOKU&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Oct 2022 14:08:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-include-two-index-events-without-using-JOIN-command/m-p/616318#M14135</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2022-10-07T14:08:23Z</dc:date>
    </item>
    <item>
      <title>Re: Include two index events without using JOIN command</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-include-two-index-events-without-using-JOIN-command/m-p/616322#M14137</link>
      <description>&lt;P&gt;Are you a magician?&lt;/P&gt;&lt;P&gt;Because your magic spell(SPL) actually worked without giving any errors.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks much&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Oct 2022 14:24:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-include-two-index-events-without-using-JOIN-command/m-p/616322#M14137</guid>
      <dc:creator>super_saiyan</dc:creator>
      <dc:date>2022-10-07T14:24:22Z</dc:date>
    </item>
    <item>
      <title>Re: Include two index events without using JOIN command</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-include-two-index-events-without-using-JOIN-command/m-p/616326#M14138</link>
      <description>&lt;P&gt;But there is only one problem.&lt;BR /&gt;I am getting multiple comments values in a single table events.&lt;/P&gt;&lt;P&gt;Can we segregate that as well ?&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/127939"&gt;@kamlesh_vaghela&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Oct 2022 14:32:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-include-two-index-events-without-using-JOIN-command/m-p/616326#M14138</guid>
      <dc:creator>super_saiyan</dc:creator>
      <dc:date>2022-10-07T14:32:32Z</dc:date>
    </item>
    <item>
      <title>Re: Include two index events without using JOIN command</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-include-two-index-events-without-using-JOIN-command/m-p/616335#M14142</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244498"&gt;@super_saiyan&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Glad to help you.&amp;nbsp;&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt; . If the solution resolved your problem then please accept the answer to the close question.&lt;/P&gt;&lt;P&gt;KV&lt;/P&gt;</description>
      <pubDate>Fri, 07 Oct 2022 15:09:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-include-two-index-events-without-using-JOIN-command/m-p/616335#M14142</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2022-10-07T15:09:03Z</dc:date>
    </item>
  </channel>
</rss>

