<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Help with Splunk query in combining two source types? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Help-with-Splunk-query-in-combining-two-source-types/m-p/646290#M223708</link>
    <description>&lt;P&gt;Hi,&lt;BR /&gt;I have two source types CardMember_cycle_data (with card member cycle date info) and CardMember_Demographic_data (with card member demographic info).&lt;/P&gt;&lt;P&gt;Both files have more than 3-4 million records each.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;(all dates are in MM/DD/YYYY format)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;CardMember_cycle_data&lt;BR /&gt;CM_id&amp;nbsp; &amp;nbsp;Cycle_Date&lt;BR /&gt;CM1&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;05/01/2023&lt;BR /&gt;CM1&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;06/01/2023&lt;BR /&gt;CM2&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;04/03/2023&lt;BR /&gt;CM2&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;05/03/2023&lt;BR /&gt;CM2&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;06/03/2023&lt;BR /&gt;--------------------------&lt;/P&gt;&lt;P&gt;CardMember_Demographic_data&lt;BR /&gt;CM_id Transaction_Dt&amp;nbsp; &amp;nbsp;Prod_Code&lt;BR /&gt;CM1&amp;nbsp; &amp;nbsp; &amp;nbsp;01/02/2020&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; CR&lt;BR /&gt;CM1&amp;nbsp; &amp;nbsp; &amp;nbsp;05/28/2023&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; XX&lt;BR /&gt;CM1&amp;nbsp; &amp;nbsp; &amp;nbsp;06/07/2023&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; AB&lt;BR /&gt;CM2&amp;nbsp; &amp;nbsp; &amp;nbsp;04/14/2023&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; YY&lt;BR /&gt;CM2&amp;nbsp; &amp;nbsp; &amp;nbsp;06/01/2023&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; CD&lt;/P&gt;&lt;P&gt;My need is -&lt;BR /&gt;For each Card Member present in CardMember_cycle_data I need to get the latest Prod_Code as of LATEST Cycle_Date.&lt;BR /&gt;Hence the output will be:&lt;BR /&gt;CardMember&amp;nbsp; &amp;nbsp; &amp;nbsp;Latest_Cycle_Date&amp;nbsp; &amp;nbsp; &amp;nbsp;Prod_Code&lt;BR /&gt;CM1&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;06/01/2023&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; XX&lt;BR /&gt;CM2&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;06/03/2023&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; CD&lt;/P&gt;</description>
    <pubDate>Thu, 08 Jun 2023 23:42:02 GMT</pubDate>
    <dc:creator>sujoybose77</dc:creator>
    <dc:date>2023-06-08T23:42:02Z</dc:date>
    <item>
      <title>Help with Splunk query in combining two source types?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-Splunk-query-in-combining-two-source-types/m-p/646290#M223708</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;I have two source types CardMember_cycle_data (with card member cycle date info) and CardMember_Demographic_data (with card member demographic info).&lt;/P&gt;&lt;P&gt;Both files have more than 3-4 million records each.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;(all dates are in MM/DD/YYYY format)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;CardMember_cycle_data&lt;BR /&gt;CM_id&amp;nbsp; &amp;nbsp;Cycle_Date&lt;BR /&gt;CM1&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;05/01/2023&lt;BR /&gt;CM1&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;06/01/2023&lt;BR /&gt;CM2&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;04/03/2023&lt;BR /&gt;CM2&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;05/03/2023&lt;BR /&gt;CM2&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;06/03/2023&lt;BR /&gt;--------------------------&lt;/P&gt;&lt;P&gt;CardMember_Demographic_data&lt;BR /&gt;CM_id Transaction_Dt&amp;nbsp; &amp;nbsp;Prod_Code&lt;BR /&gt;CM1&amp;nbsp; &amp;nbsp; &amp;nbsp;01/02/2020&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; CR&lt;BR /&gt;CM1&amp;nbsp; &amp;nbsp; &amp;nbsp;05/28/2023&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; XX&lt;BR /&gt;CM1&amp;nbsp; &amp;nbsp; &amp;nbsp;06/07/2023&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; AB&lt;BR /&gt;CM2&amp;nbsp; &amp;nbsp; &amp;nbsp;04/14/2023&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; YY&lt;BR /&gt;CM2&amp;nbsp; &amp;nbsp; &amp;nbsp;06/01/2023&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; CD&lt;/P&gt;&lt;P&gt;My need is -&lt;BR /&gt;For each Card Member present in CardMember_cycle_data I need to get the latest Prod_Code as of LATEST Cycle_Date.&lt;BR /&gt;Hence the output will be:&lt;BR /&gt;CardMember&amp;nbsp; &amp;nbsp; &amp;nbsp;Latest_Cycle_Date&amp;nbsp; &amp;nbsp; &amp;nbsp;Prod_Code&lt;BR /&gt;CM1&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;06/01/2023&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; XX&lt;BR /&gt;CM2&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;06/03/2023&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; CD&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2023 23:42:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-Splunk-query-in-combining-two-source-types/m-p/646290#M223708</guid>
      <dc:creator>sujoybose77</dc:creator>
      <dc:date>2023-06-08T23:42:02Z</dc:date>
    </item>
    <item>
      <title>Re: Need help with Splunk query in combining two source types</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-Splunk-query-in-combining-two-source-types/m-p/646297#M223709</link>
      <description>&lt;P&gt;Judging by your expected output, you want the last product code for the member as of the latest date in the cycle data i.e. not the latest product code for the member if it is after the last cycle date.&lt;/P&gt;&lt;P&gt;In order to do date comparisons, you will need to parse the date strings into internal date format. If you search both data sources at the same time (or append one search after the other), you can do something like this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eval _time=coalesce(strptime(Cycle_Date,"%m/%d/%Y"), strptime(Transaction_Dt,"%m/%d/%Y"))
| sort _time
| streamstats latest(Prod_Code) as Prod_Code by CM_id
| where isnotnull(Cycle_Date)
| stats latest(Cycle_Date) as Cycle_Date latest(Prod_Code) as Prod_Code by CM_id&lt;/LI-CODE&gt;&lt;P&gt;Note that this may not quite work if the date are the same in the two sources&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2023 10:02:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-Splunk-query-in-combining-two-source-types/m-p/646297#M223709</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-06-08T10:02:52Z</dc:date>
    </item>
  </channel>
</rss>

