<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Joining Tables in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Joining-Tables/m-p/584348#M203487</link>
    <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need your help please, I have two tables resulting from two searches and I need to join these two tables to make a cumulative bar chart according to date.&lt;/P&gt;&lt;P&gt;My tables are&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="crmarley20_0-1644425055153.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/17897i3623B996C7EEF8B4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="crmarley20_0-1644425055153.png" alt="crmarley20_0-1644425055153.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="crmarley20_1-1644425077542.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/17898iAB68FD807E02F7A9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="crmarley20_1-1644425077542.png" alt="crmarley20_1-1644425077542.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;What I want to achieve is:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;TABLE border="1" width="86.22449240881645%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;Datum&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;A1&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;A2&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;A3&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;A4&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;A5&lt;/TD&gt;&lt;TD width="7.142857142857143%" height="25px"&gt;A6&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD height="25px"&gt;2022-02-08&lt;/TD&gt;&lt;TD height="25px"&gt;5.7&lt;/TD&gt;&lt;TD height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD height="25px"&gt;3.7&lt;/TD&gt;&lt;TD height="25px"&gt;1.9&lt;/TD&gt;&lt;TD height="25px"&gt;4.56&lt;/TD&gt;&lt;TD height="25px"&gt;90.3&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 09 Feb 2022 16:48:41 GMT</pubDate>
    <dc:creator>crmarley20</dc:creator>
    <dc:date>2022-02-09T16:48:41Z</dc:date>
    <item>
      <title>Joining Tables</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Joining-Tables/m-p/584348#M203487</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need your help please, I have two tables resulting from two searches and I need to join these two tables to make a cumulative bar chart according to date.&lt;/P&gt;&lt;P&gt;My tables are&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="crmarley20_0-1644425055153.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/17897i3623B996C7EEF8B4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="crmarley20_0-1644425055153.png" alt="crmarley20_0-1644425055153.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="crmarley20_1-1644425077542.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/17898iAB68FD807E02F7A9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="crmarley20_1-1644425077542.png" alt="crmarley20_1-1644425077542.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;What I want to achieve is:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;TABLE border="1" width="86.22449240881645%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;Datum&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;A1&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;A2&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;A3&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;A4&lt;/TD&gt;&lt;TD width="14.285714285714286%" height="25px"&gt;A5&lt;/TD&gt;&lt;TD width="7.142857142857143%" height="25px"&gt;A6&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD height="25px"&gt;2022-02-08&lt;/TD&gt;&lt;TD height="25px"&gt;5.7&lt;/TD&gt;&lt;TD height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD height="25px"&gt;3.7&lt;/TD&gt;&lt;TD height="25px"&gt;1.9&lt;/TD&gt;&lt;TD height="25px"&gt;4.56&lt;/TD&gt;&lt;TD height="25px"&gt;90.3&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Feb 2022 16:48:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Joining-Tables/m-p/584348#M203487</guid>
      <dc:creator>crmarley20</dc:creator>
      <dc:date>2022-02-09T16:48:41Z</dc:date>
    </item>
    <item>
      <title>Re: Joining Tables</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Joining-Tables/m-p/584352#M203489</link>
      <description>&lt;P&gt;What are your two searches?&lt;/P&gt;</description>
      <pubDate>Wed, 09 Feb 2022 17:12:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Joining-Tables/m-p/584352#M203489</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-02-09T17:12:39Z</dc:date>
    </item>
    <item>
      <title>Re: Joining Tables</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Joining-Tables/m-p/584455#M203514</link>
      <description>&lt;P&gt;Something like this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;first table's search&amp;gt; | chart sum(mid_result) over segment
| append [| search &amp;lt;second table's search&amp;gt;]
| stats sum(*) as * by Schiche_Datum
| rename Schiche_Datum as Datum&lt;/LI-CODE&gt;&lt;P&gt;Kindly ignore typos and fix column names if I mis-typed it.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Feb 2022 06:58:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Joining-Tables/m-p/584455#M203514</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2022-02-10T06:58:10Z</dc:date>
    </item>
    <item>
      <title>Re: Joining Tables</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Joining-Tables/m-p/584461#M203519</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;You have two different formatted tables. You might want to transform the structure either on first search or second.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;first_search
| join type=left Schicht_Datum [ second_search | untable Schicht_Datum segment mid_result ]
| xyseries Schicht_Datum segment mid_result&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Feb 2022 07:15:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Joining-Tables/m-p/584461#M203519</guid>
      <dc:creator>BahadirS</dc:creator>
      <dc:date>2022-02-10T07:15:28Z</dc:date>
    </item>
  </channel>
</rss>

