Getting Data In

How do you append data from a different source in the same Index?

maheshsat
Explorer

I have one Index that has two different sources. One source has current data and another has historical data. Both have the same fields. I want to append data current in historical data incase there are any changes in current data by user that should be reflected in historical data. I want one side current data in column, & on the other side, there would be historical data in another column.

Trying below command

source="historical" PERIOD="Q1" YEAR="2012" | Table PERIOD, YEAR | append [index=prod source="current"  PERIOD="Q2" YEAR="2012" | Table PERIOD, YEAR]
Tags (1)
0 Karma
1 Solution

Akumar294
Path Finder

Please try like below:

index="your index" source="historical" PERIOD="Q1" YEAR="2012" 
|table PERIOD, YEAR 
|join [search index=prod source="current" PERIOD="Q2" YEAR="2012" 
|table PERIOD, YEAR]

View solution in original post

0 Karma

Akumar294
Path Finder

Please try like below:

index="your index" source="historical" PERIOD="Q1" YEAR="2012" 
|table PERIOD, YEAR 
|join [search index=prod source="current" PERIOD="Q2" YEAR="2012" 
|table PERIOD, YEAR]
0 Karma

Akumar294
Path Finder

If above solution resolved your problem, can you please accept the answer?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...