<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk for DBA in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Splunk-for-DBA/m-p/692406#M235676</link>
    <description>&lt;P&gt;I have been trying to create some analyzes in splunk for&amp;nbsp; a few week now. Sometimes I succeed, sometimes I fail. I appreciate a lot of help from community users - it helps a lot. And the results sometimes are amazing.&lt;/P&gt;&lt;P&gt;Anyway I still feel not comfortable and experience a lot of problems with syntax and rules of splunk language .&amp;nbsp; I am thinking about a page/tutorial/blog/youtube channel , something like Splunk for DBA - relational DBA! . To read about theory , rules and syntax commands with examples&amp;nbsp; like stats, join, append, timecharts and other who can manipulate with multiple &lt;STRIKE&gt;table&lt;/STRIKE&gt; indexes their relations and aggregations. Of course this community is a mine of examples and recipes but maybe there is a place where such topics are described and explained in more affordable structured way.&amp;nbsp;&lt;/P&gt;&lt;P&gt;any ideas , hints&lt;/P&gt;&lt;P&gt;K.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 04 Jul 2024 12:33:23 GMT</pubDate>
    <dc:creator>kp_pl</dc:creator>
    <dc:date>2024-07-04T12:33:23Z</dc:date>
    <item>
      <title>Splunk for DBA</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-for-DBA/m-p/692406#M235676</link>
      <description>&lt;P&gt;I have been trying to create some analyzes in splunk for&amp;nbsp; a few week now. Sometimes I succeed, sometimes I fail. I appreciate a lot of help from community users - it helps a lot. And the results sometimes are amazing.&lt;/P&gt;&lt;P&gt;Anyway I still feel not comfortable and experience a lot of problems with syntax and rules of splunk language .&amp;nbsp; I am thinking about a page/tutorial/blog/youtube channel , something like Splunk for DBA - relational DBA! . To read about theory , rules and syntax commands with examples&amp;nbsp; like stats, join, append, timecharts and other who can manipulate with multiple &lt;STRIKE&gt;table&lt;/STRIKE&gt; indexes their relations and aggregations. Of course this community is a mine of examples and recipes but maybe there is a place where such topics are described and explained in more affordable structured way.&amp;nbsp;&lt;/P&gt;&lt;P&gt;any ideas , hints&lt;/P&gt;&lt;P&gt;K.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2024 12:33:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-for-DBA/m-p/692406#M235676</guid>
      <dc:creator>kp_pl</dc:creator>
      <dc:date>2024-07-04T12:33:23Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for DBA</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-for-DBA/m-p/692409#M235678</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Have you already seen this&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/SQLtoSplunk" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/SQLtoSplunk&lt;/A&gt;?&lt;/P&gt;&lt;P&gt;It could give some hints how things are done on Splunk vs SQL. BUT you shouldn't follow this too much as how Splunk is working is totally different than in SQL. I suppose that there are many conf presentations which could help you to better understand how to work with Splunk. Some other good source of work with Splunk are:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="https://conf.splunk.com/watch/conf-online.html?locale=watch#/" target="_blank"&gt;https://conf.splunk.com/watch/conf-online.html?locale=watch#/&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://education.splunk.com/Saba/Web_spf/NA10P2PRD105/app/catalog/search?searchText=search%20beginner&amp;amp;selectedTab=LEARNINGEVENT&amp;amp;filter=%7B%22LEARNINGEVENTTYPEFACET%22:%7B%22label%22:null,%22values%22:%20%5B%7B%22facetValueId%22:%221%22,%22facetValueLabel%22:null%7D%5D%7D%7D" target="_blank"&gt;https://education.splunk.com/Saba/Web_spf/NA10P2PRD105/app/catalog/search?searchText=search%20beginner&amp;amp;selectedTab=LEARNINGEVENT&amp;amp;filter=%7B%22LEARNINGEVENTTYPEFACET%22:%7B%22label%22:null,%22values%22:%20%5B%7B%22facetValueId%22:%221%22,%22facetValueLabel%22:null%7D%5D%7D%7D&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Search/GetstartedwithSearch" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Search/GetstartedwithSearch&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/SearchTutorial/WelcometotheSearchTutorial" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/SearchTutorial/WelcometotheSearchTutorial&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://www.youtube.com/results?search_query=splunk+bsides" target="_blank"&gt;https://www.youtube.com/results?search_query=splunk+bsides&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2024 13:30:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-for-DBA/m-p/692409#M235678</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2024-07-04T13:30:47Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for DBA</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-for-DBA/m-p/692418#M235681</link>
      <description>&lt;P&gt;wow , the first link is a good source of knowledge &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp; thanks a lot.&amp;nbsp;&amp;nbsp; There is one more sql I need to implement in splunk but it is not present there.&lt;BR /&gt;Maybe you could help . The most efficient way to inner join is something like :&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;index=db  OR index=app
| eval join=if(index="db",processId,pid)
| stats sum(rows) sum(cputime) by join
&lt;/LI-CODE&gt;
&lt;P&gt;&lt;BR /&gt;But how to join two tables with multicolumn key&amp;nbsp; ?&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;PRE&gt;&lt;EM&gt;SELECT *
FROM mytable1
INNER JOIN mytable2
ON (mytable1.mycolumn= mytable2.mycolumn AND mytable1.mycolumn2= mytable2.mycolumn2)&lt;/EM&gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2024 17:32:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-for-DBA/m-p/692418#M235681</guid>
      <dc:creator>kp_pl</dc:creator>
      <dc:date>2024-07-04T17:32:28Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for DBA</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-for-DBA/m-p/692420#M235683</link>
      <description>&lt;P&gt;&lt;A href="https://conf.splunk.com/files/2020/slides/TRU1761C.pdf" target="_blank" rel="noopener"&gt;https://conf.splunk.com/files/2020/slides/TRU1761C.pdf&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Here I found a good pdf ... in fact&amp;nbsp;&lt;SPAN class=""&gt; &lt;A class="" href="https://community.splunk.com/t5/user/viewprofilepage/user-id/67425" target="_self"&gt;starcher&lt;/A&gt; found and I found his post .&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2024 14:51:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-for-DBA/m-p/692420#M235683</guid>
      <dc:creator>kp_pl</dc:creator>
      <dc:date>2024-07-04T14:51:54Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for DBA</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-for-DBA/m-p/692484#M235700</link>
      <description>That is one excellent source. There are some others too.&lt;BR /&gt;Here is one old post SQL vs. Splunk inner/outer join &lt;A href="https://community.splunk.com/t5/Splunk-Search/What-is-the-relation-between-the-Splunk-inner-left-join-and-the/m-p/391288/thread-id/113948" target="_blank"&gt;https://community.splunk.com/t5/Splunk-Search/What-is-the-relation-between-the-Splunk-inner-left-join-and-the/m-p/391288/thread-id/113948&lt;/A&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 05 Jul 2024 14:10:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-for-DBA/m-p/692484#M235700</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2024-07-05T14:10:18Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for DBA</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-for-DBA/m-p/692493#M235702</link>
      <description>&lt;P&gt;YEAH!&amp;nbsp; It is really useful.&amp;nbsp; It helps a lot!&lt;BR /&gt;2 karmas :&amp;nbsp; one for You , second one for &lt;SPAN class=""&gt;&lt;A class="" href="https://community.splunk.com/t5/user/viewprofilepage/user-id/1406" target="_self"&gt;woodcock&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;K&lt;STRONG&gt;.&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jul 2024 14:49:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-for-DBA/m-p/692493#M235702</guid>
      <dc:creator>kp_pl</dc:creator>
      <dc:date>2024-07-05T14:49:27Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for DBA</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-for-DBA/m-p/692541#M235714</link>
      <description>&lt;P&gt;I understand what drove Splunk to prepare this page but this is best avoided. It encourages users to use some anti-patterns which are not and should not normally be used in Splunk.&lt;/P&gt;&lt;P&gt;Splunk is very different from RDBMS so it needs another "way of thinking". I find it easier to compare Splunk search to processing data with unix shell (I also suspect that choice of the pipe sign to delimit the steps in the pipeline is not accidental &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; ).&lt;/P&gt;&lt;P&gt;And as a rule of thumb the &lt;EM&gt;join&lt;/EM&gt; command should typically not be used with Splunk. (yes, there are use cases for it so it's there but it's not as common as in SQL).&lt;/P&gt;&lt;P&gt;I don't know what you mean by "multicolumn key" in this context but you can either use &lt;EM&gt;stats&lt;/EM&gt; with multiple &lt;EM&gt;by&lt;/EM&gt; fields or - if you mean it the opposite way - you can create a synthetic field to split by. Like&lt;/P&gt;&lt;PRE&gt;| eval splitfield=field1."-".field2."-".field3&lt;BR /&gt;| stats count by splitfield&lt;/PRE&gt;&lt;P&gt;Just watch for cardinality...&lt;/P&gt;&lt;P&gt;EDIT: Oh, I didn't see your SQL example. So you can make such syntetic fields from both kinds of data (possibly using conditional eval to calculate them separately for each subset). And then stats by those fields.&lt;/P&gt;</description>
      <pubDate>Sat, 06 Jul 2024 10:25:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-for-DBA/m-p/692541#M235714</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-07-06T10:25:26Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk for DBA</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-for-DBA/m-p/692958#M235837</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;, thanks for Your comment - true , Splunk is completely different than RDBMS &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp; For a guy like me who work with Oracle/Mssql/othersDB is like a torture to create suitable "queries" . Anyway I need to do some jobs using splunk so I need to look for a help from You.&amp;nbsp;&lt;BR /&gt;I am surprised I found a way to link two tables where two columns are keys&amp;nbsp; - the most ridiculous way (from my point of view) concatenate two strings/keys is correct !&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jul 2024 04:54:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-for-DBA/m-p/692958#M235837</guid>
      <dc:creator>kp_pl</dc:creator>
      <dc:date>2024-07-11T04:54:06Z</dc:date>
    </item>
  </channel>
</rss>

