Getting Data In

Inner Join

Siddharthnegi
Contributor

Let say I have 2 lookup files , lookup1  has 50 values and other have 150 values
so when I inner join  lookup1 to lookup 2 it gives me low results but when i reverse it results change and are higher.

Labels (1)
0 Karma

glc_slash_it
Path Finder

First load the lookups and then group both realms using stats.

Try to do something like this and adjust it to your needs,  assuming there is a field that is common in both data sets:

 

|inputlookup lookup1
|inputlookup lookup2 append=true
| stats values(fieldA) AS fieldA (...) by fieldB_common_in_both_datasets

 

 

If there is not common field, use rename or eval to create that common field before the stats:

| inputlookup lookup1
| inputlookup lookup2 append=true
| rename fieldC as fieldB
| stats values(fieldA) AS fieldA (...) by fieldB

 

 

 

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...