Is it possible to implement anything like SQL "in" clause in splunk?
select a from A where b in (select b from B)
inner join is not a good way, as I see, when there are several million of rows in A and a couple in B.
any ideas? thank you in advance
Yes. Use subsearches.
sourcetype=a [sourcetype=B | fields b] | fields a
View solution in original post