<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Query on get Combined and Unique Values in Reporting</title>
    <link>https://community.splunk.com/t5/Reporting/Query-on-get-Combined-and-Unique-Values/m-p/675882#M12357</link>
    <description>&lt;P&gt;Please share your current searches and some sample events, and what your expected result would look like (anonymised of course)&lt;/P&gt;</description>
    <pubDate>Tue, 30 Jan 2024 10:17:53 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2024-01-30T10:17:53Z</dc:date>
    <item>
      <title>Query on get Combined and Unique Values</title>
      <link>https://community.splunk.com/t5/Reporting/Query-on-get-Combined-and-Unique-Values/m-p/675871#M12356</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have&amp;nbsp; database1 and database2,&amp;nbsp; I have query1 to get the data from database1 and query2 to get data from database2. query3 to get unique values from databse2 which doesn't exist in database1.&lt;/P&gt;&lt;P&gt;Now my requirement is to combine the common values in both the databases using a query1 &amp;amp; query2 and also unique values from query2 from database2 which doesn't exist in database1.&lt;/P&gt;&lt;P&gt;Please provide me the Splunk query.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2024 09:54:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Query-on-get-Combined-and-Unique-Values/m-p/675871#M12356</guid>
      <dc:creator>Mallik657</dc:creator>
      <dc:date>2024-01-30T09:54:50Z</dc:date>
    </item>
    <item>
      <title>Re: Query on get Combined and Unique Values</title>
      <link>https://community.splunk.com/t5/Reporting/Query-on-get-Combined-and-Unique-Values/m-p/675882#M12357</link>
      <description>&lt;P&gt;Please share your current searches and some sample events, and what your expected result would look like (anonymised of course)&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2024 10:17:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Query-on-get-Combined-and-Unique-Values/m-p/675882#M12357</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-01-30T10:17:53Z</dc:date>
    </item>
    <item>
      <title>Re: Query on get Combined and Unique Values</title>
      <link>https://community.splunk.com/t5/Reporting/Query-on-get-Combined-and-Unique-Values/m-p/675908#M12358</link>
      <description>&lt;P&gt;Result should get common in both databases and also unique/rest values from database2. Please help me with query.&lt;/P&gt;&lt;TABLE width="209"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="74"&gt;Databse1&lt;/TD&gt;&lt;TD width="71"&gt;Database2&lt;/TD&gt;&lt;TD width="64"&gt;Result&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;A&lt;/TD&gt;&lt;TD&gt;A&lt;/TD&gt;&lt;TD&gt;A&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;B&lt;/TD&gt;&lt;TD&gt;B&lt;/TD&gt;&lt;TD&gt;B&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;C&lt;/TD&gt;&lt;TD&gt;C&lt;/TD&gt;&lt;TD&gt;C&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;D&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;E&lt;/TD&gt;&lt;TD&gt;E&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;E&lt;/TD&gt;&lt;TD&gt;F&lt;/TD&gt;&lt;TD&gt;F&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;G&lt;/TD&gt;&lt;TD&gt;G&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;H&lt;/TD&gt;&lt;TD&gt;H&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Tue, 30 Jan 2024 13:46:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Query-on-get-Combined-and-Unique-Values/m-p/675908#M12358</guid>
      <dc:creator>Mallik657</dc:creator>
      <dc:date>2024-01-30T13:46:31Z</dc:date>
    </item>
    <item>
      <title>Re: Query on get Combined and Unique Values</title>
      <link>https://community.splunk.com/t5/Reporting/Query-on-get-Combined-and-Unique-Values/m-p/675942#M12359</link>
      <description>&lt;LI-CODE lang="markup"&gt;| makeresults count=5
| fields - _time
| streamstats count as row
| eval database1=mvindex(split("ABCDE",""),row - 1)
| fields - row
| appendcols
    [| makeresults count=7
    | streamstats count as row
    | eval database2=mvindex(split("ABCEFGH",""),row - 1)
    | fields - row]
| eval result=database2&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 30 Jan 2024 16:09:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Query-on-get-Combined-and-Unique-Values/m-p/675942#M12359</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-01-30T16:09:46Z</dc:date>
    </item>
  </channel>
</rss>

