All Apps and Add-ons

sql "IN" in splunk

0range
Communicator

Hello!
Is it possible to implement anything like SQL "in" clause in splunk?

like this:
select a from A where b in (select b from B)

inner join is not a good way, as I see, when there are several million of rows in A and a couple in B.

any ideas? thank you in advance

Tags (1)
0 Karma
1 Solution

Ayn
Legend

Yes. Use subsearches.

http://docs.splunk.com/Documentation/Splunk/6.0.3/SearchTutorial/Useasubsearch

sourcetype=a [sourcetype=B | fields b] | fields a

View solution in original post

Ayn
Legend

Yes. Use subsearches.

http://docs.splunk.com/Documentation/Splunk/6.0.3/SearchTutorial/Useasubsearch

sourcetype=a [sourcetype=B | fields b] | fields a
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...