<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Part2:  How to join two different result sharing common field? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Part2-How-to-join-two-different-result-sharing-common-field/m-p/636335#M220995</link>
    <description>&lt;P&gt;Why are you using inputlookup when all you appear to need is lookup?&lt;/P&gt;&lt;P&gt;Is there something else in your usecase that requires you to use inputlookup?&lt;/P&gt;</description>
    <pubDate>Tue, 28 Mar 2023 14:27:23 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2023-03-28T14:27:23Z</dc:date>
    <item>
      <title>Part2:  How to join two different result sharing common field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Part2-How-to-join-two-different-result-sharing-common-field/m-p/636315#M220989</link>
      <description>&lt;P&gt;Let say I have a result below&lt;BR /&gt;index = indextest&lt;BR /&gt;source=stest&lt;/P&gt;&lt;P&gt;bunch of evals = evals&lt;/P&gt;&lt;P&gt;sourcetype=sttext&lt;BR /&gt;| table ID Status Remark&amp;nbsp;Values&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ID&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Status&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Remark&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Values&lt;/P&gt;&lt;P&gt;11&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;PASS&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; CHECKED&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;something something hello&lt;/P&gt;&lt;P&gt;371&amp;nbsp; &amp;nbsp; &amp;nbsp; FAILED&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;CONFIRMED&amp;nbsp; &amp;nbsp; someting hello SOME&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;let say I want to input another field from a inputlookup that is correlated with the ID number.&lt;/P&gt;&lt;P&gt;ex)&lt;/P&gt;&lt;P&gt;| inputlookup test&lt;/P&gt;&lt;P&gt;|table ID ActualName&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ID&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;ActualName&lt;/P&gt;&lt;P&gt;11&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;McDonald&lt;/P&gt;&lt;P&gt;371&amp;nbsp; &amp;nbsp; BurgerKing&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HOW TO simply input that result into the first query so that I can get a result as below?&lt;/P&gt;&lt;P&gt;ID&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ActualValue&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Status&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Remark&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Values&lt;/P&gt;&lt;P&gt;11&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;McDonald&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;PASS&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; CHECKED&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;something something hello&lt;/P&gt;&lt;P&gt;371&amp;nbsp; &amp;nbsp; &amp;nbsp; BurgerKing&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; FAILED&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;CONFIRMED&amp;nbsp; &amp;nbsp; someting hello SOME&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NOTE&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;when I try this,&lt;/P&gt;&lt;P&gt;index = indextest&lt;BR /&gt;source=stest&lt;/P&gt;&lt;P&gt;bunch of evals = evals&lt;/P&gt;&lt;P&gt;sourcetype=sttext&lt;BR /&gt;|append [ | inputlookup test]&lt;BR /&gt;|stats values("ID") as ID, values ("Actual Value") as "Actual Value" ...and so on... by System&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;result comes out&lt;/P&gt;&lt;P&gt;ID&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ActualValue&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Status&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Remark&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Values&lt;/P&gt;&lt;P&gt;11 , 371&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;McDonald ,&amp;nbsp;BurgerKing &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;PASS, FAILED&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; CHECKED&amp;nbsp; ,CONFIRMED&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;something something hello ,&amp;nbsp;someting hello SOME&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;it's not separated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Simply how to insert a inputlookup result to a table that shares a one common field.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 13:22:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Part2-How-to-join-two-different-result-sharing-common-field/m-p/636315#M220989</guid>
      <dc:creator>yohhpark</dc:creator>
      <dc:date>2023-03-28T13:22:36Z</dc:date>
    </item>
    <item>
      <title>Re: Part2:  How to join two different result sharing common field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Part2-How-to-join-two-different-result-sharing-common-field/m-p/636323#M220991</link>
      <description>&lt;LI-CODE lang="markup"&gt;index = indextest
source=stest

bunch of evals = evals

sourcetype=sttext
| lookup test ID
| table ID ActualName Status Remark Values&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 28 Mar 2023 13:56:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Part2-How-to-join-two-different-result-sharing-common-field/m-p/636323#M220991</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-03-28T13:56:15Z</dc:date>
    </item>
    <item>
      <title>Re: Part2:  How to join two different result sharing common field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Part2-How-to-join-two-different-result-sharing-common-field/m-p/636333#M220993</link>
      <description>&lt;P&gt;I've tried. it's not working.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;index=test&lt;/P&gt;&lt;P&gt;|table System Status&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;simple need to input&lt;/P&gt;&lt;P&gt;|inputlookup test123&lt;/P&gt;&lt;P&gt;|table System IDnumber&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so that result show&lt;/P&gt;&lt;P&gt;System IDnumber Status&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;struggling &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 14:24:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Part2-How-to-join-two-different-result-sharing-common-field/m-p/636333#M220993</guid>
      <dc:creator>yohhpark</dc:creator>
      <dc:date>2023-03-28T14:24:34Z</dc:date>
    </item>
    <item>
      <title>Re: Part2:  How to join two different result sharing common field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Part2-How-to-join-two-different-result-sharing-common-field/m-p/636335#M220995</link>
      <description>&lt;P&gt;Why are you using inputlookup when all you appear to need is lookup?&lt;/P&gt;&lt;P&gt;Is there something else in your usecase that requires you to use inputlookup?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 14:27:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Part2-How-to-join-two-different-result-sharing-common-field/m-p/636335#M220995</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-03-28T14:27:23Z</dc:date>
    </item>
    <item>
      <title>Re: Part2:  How to join two different result sharing common field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Part2-How-to-join-two-different-result-sharing-common-field/m-p/636345#M220999</link>
      <description>&lt;P&gt;because it's subsearch.&lt;/P&gt;&lt;P&gt;inputlookup is required.&amp;nbsp;&lt;/P&gt;&lt;P&gt;index does not contain such information.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 15:33:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Part2-How-to-join-two-different-result-sharing-common-field/m-p/636345#M220999</guid>
      <dc:creator>yohhpark</dc:creator>
      <dc:date>2023-03-28T15:33:27Z</dc:date>
    </item>
    <item>
      <title>Re: Part2:  How to join two different result sharing common field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Part2-How-to-join-two-different-result-sharing-common-field/m-p/636349#M221001</link>
      <description>&lt;P&gt;From your example, i.e.&lt;/P&gt;&lt;P&gt;ID&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Status&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Remark&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Values&lt;/P&gt;&lt;P&gt;11&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;PASS&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; CHECKED&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;something something hello&lt;/P&gt;&lt;P&gt;371&amp;nbsp; &amp;nbsp; &amp;nbsp; FAILED&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;CONFIRMED&amp;nbsp; &amp;nbsp; someting hello SOME&lt;/P&gt;&lt;P&gt;becoming&lt;/P&gt;&lt;P&gt;ID&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ActualValue&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Status&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Remark&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Values&lt;/P&gt;&lt;P&gt;11&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;McDonald&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;PASS&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; CHECKED&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;something something hello&lt;/P&gt;&lt;P&gt;371&amp;nbsp; &amp;nbsp; &amp;nbsp; BurgerKing&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; FAILED&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;CONFIRMED&amp;nbsp; &amp;nbsp; someting hello SOME&lt;/P&gt;&lt;P&gt;using a lookup called test with these contents&lt;/P&gt;&lt;P&gt;ID&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;ActualName&lt;/P&gt;&lt;P&gt;11&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;McDonald&lt;/P&gt;&lt;P&gt;371&amp;nbsp; &amp;nbsp; BurgerKing&lt;/P&gt;&lt;P&gt;a lookup as I showed would do this&lt;/P&gt;&lt;P&gt;Exactly how is your actual situation different from the above example which makes a simple lookup not work?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 15:47:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Part2-How-to-join-two-different-result-sharing-common-field/m-p/636349#M221001</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-03-28T15:47:02Z</dc:date>
    </item>
    <item>
      <title>Re: Part2:  How to join two different result sharing common field?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Part2-How-to-join-two-different-result-sharing-common-field/m-p/636361#M221007</link>
      <description>&lt;P&gt;I have used your idea.&lt;/P&gt;&lt;P&gt;I got the table first&lt;/P&gt;&lt;P&gt;ID Status Remark&lt;BR /&gt;&lt;BR /&gt;then use lookup to match the ID and output the ActualName&lt;BR /&gt;&lt;BR /&gt;then print the table again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;REASON why didn't work first time was that the lookup table did not have the field as "ID" it had it as such as 'title'. and the original SPL search. therefore, I have renamed ID to title, then did the lookup, and THEN switched the title back to ID and table them out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;worked!! thank you so much. learned a lot&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 16:18:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Part2-How-to-join-two-different-result-sharing-common-field/m-p/636361#M221007</guid>
      <dc:creator>yohhpark</dc:creator>
      <dc:date>2023-03-28T16:18:39Z</dc:date>
    </item>
  </channel>
</rss>

