Hello!
Is it possible to implement anything like SQL "in" clause in splunk?
like this:
select a from A where b in (select b from B)
inner join is not a good way, as I see, when there are several million of rows in A and a couple in B.
any ideas? thank you in advance
Yes. Use subsearches.
http://docs.splunk.com/Documentation/Splunk/6.0.3/SearchTutorial/Useasubsearch
sourcetype=a [sourcetype=B | fields b] | fields a
Yes. Use subsearches.
http://docs.splunk.com/Documentation/Splunk/6.0.3/SearchTutorial/Useasubsearch
sourcetype=a [sourcetype=B | fields b] | fields a