<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Join by time range in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Join-by-time-range/m-p/526835#M148708</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Possible to join 2 search results like following?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Set 1:&lt;/P&gt;&lt;P&gt;_time&amp;nbsp;&lt;/P&gt;&lt;P&gt;field1&lt;/P&gt;&lt;P&gt;field2&lt;/P&gt;&lt;P&gt;field3 (common field)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Set 2:&lt;/P&gt;&lt;P&gt;_time&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;fieldA (multiple values, contains start/end time)&amp;nbsp;&lt;/P&gt;&lt;P&gt;fieldB&amp;nbsp;&lt;/P&gt;&lt;P&gt;field3 (common field)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then join with common field3, together with:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;fieldA (start) &amp;lt; _time (Set1) &amp;lt; fieldA (end)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks a lot.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;/stwong&lt;/P&gt;</description>
    <pubDate>Wed, 28 Oct 2020 11:15:56 GMT</pubDate>
    <dc:creator>stwong</dc:creator>
    <dc:date>2020-10-28T11:15:56Z</dc:date>
    <item>
      <title>Join by time range</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Join-by-time-range/m-p/526835#M148708</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Possible to join 2 search results like following?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Set 1:&lt;/P&gt;&lt;P&gt;_time&amp;nbsp;&lt;/P&gt;&lt;P&gt;field1&lt;/P&gt;&lt;P&gt;field2&lt;/P&gt;&lt;P&gt;field3 (common field)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Set 2:&lt;/P&gt;&lt;P&gt;_time&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;fieldA (multiple values, contains start/end time)&amp;nbsp;&lt;/P&gt;&lt;P&gt;fieldB&amp;nbsp;&lt;/P&gt;&lt;P&gt;field3 (common field)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then join with common field3, together with:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;fieldA (start) &amp;lt; _time (Set1) &amp;lt; fieldA (end)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks a lot.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;/stwong&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2020 11:15:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Join-by-time-range/m-p/526835#M148708</guid>
      <dc:creator>stwong</dc:creator>
      <dc:date>2020-10-28T11:15:56Z</dc:date>
    </item>
    <item>
      <title>Re: Join by time range</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Join-by-time-range/m-p/526837#M148709</link>
      <description>&lt;P&gt;Rename _time in query 2 as part of the join, then you will be able to do your comparison / filter after the join&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2020 11:20:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Join-by-time-range/m-p/526837#M148709</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-10-28T11:20:46Z</dc:date>
    </item>
    <item>
      <title>Re: Join by time range</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Join-by-time-range/m-p/526992#M148744</link>
      <description>&lt;P&gt;Thanks.&amp;nbsp; Seems if join first with common field3,&amp;nbsp; unable to do filter afterwards. Would you advise how?&amp;nbsp; Sorry for the newbie question.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2020 03:10:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Join-by-time-range/m-p/526992#M148744</guid>
      <dc:creator>stwong</dc:creator>
      <dc:date>2020-10-29T03:10:34Z</dc:date>
    </item>
    <item>
      <title>Re: Join by time range</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Join-by-time-range/m-p/527025#M148763</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/148178"&gt;@stwong&lt;/a&gt;&amp;nbsp;I don't understand what you mean. Perhaps if you gave some concrete examples of your queries and data we might be able to help more.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2020 08:55:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Join-by-time-range/m-p/527025#M148763</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-10-29T08:55:57Z</dc:date>
    </item>
  </channel>
</rss>

