All Apps and Add-ons
Highlighted

sql "IN" in splunk

Communicator

Hello!
Is it possible to implement anything like SQL "in" clause in splunk?

like this:
select a from A where b in (select b from B)

inner join is not a good way, as I see, when there are several million of rows in A and a couple in B.

any ideas? thank you in advance

Tags (1)
0 Karma
Highlighted

Re: sql "IN" in splunk

Legend

Yes. Use subsearches.

http://docs.splunk.com/Documentation/Splunk/6.0.3/SearchTutorial/Useasubsearch

sourcetype=a [sourcetype=B | fields b] | fields a

View solution in original post