DevOps & Observability
DevOps, AppDev, and tool-chains, oh my!

Joining two searches based on one common filed

sumandevops
Engager

I have an issue, I have 2 separate searches 

1) Comes with Emp id and tempid

2) comes with Emp id 

 

I need to join 2 searches based on group by tempid

 

Thanks

 

 

Tags (1)
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @sumandevops,

You can join to searches using join or stats command but group by field should be exists on both search results. In your case you can only join group by Empid. If you can provide your searches (anonymized) we can help better.

If this reply helps you an upvote is appreciated.
0 Karma

sumandevops
Engager

@scelikok 

My bad I have a common empid in both searches, how can I do it

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Getting Started with AIOps: Event Correlation Basics and Alert Storm Detection in ...

Getting Started with AIOps:Event Correlation Basics and Alert Storm Detection in Splunk IT Service ...

Register to Attend BSides SPL 2022 - It's all Happening October 18!

Join like-minded individuals for technical sessions on everything Splunk!  This is a community-led and run ...

What's New in Splunk Cloud Platform 9.0.2208?!

Howdy!  We are happy to share the newest updates in Splunk Cloud Platform 9.0.2208! Analysts can benefit ...