Getting Data In

Inner Join

Siddharthnegi
Contributor

Let say I have 2 lookup files , lookup1  has 50 values and other have 150 values
so when I inner join  lookup1 to lookup 2 it gives me low results but when i reverse it results change and are higher.

Labels (1)
0 Karma

glc_slash_it
Path Finder

First load the lookups and then group both realms using stats.

Try to do something like this and adjust it to your needs,  assuming there is a field that is common in both data sets:

 

|inputlookup lookup1
|inputlookup lookup2 append=true
| stats values(fieldA) AS fieldA (...) by fieldB_common_in_both_datasets

 

 

If there is not common field, use rename or eval to create that common field before the stats:

| inputlookup lookup1
| inputlookup lookup2 append=true
| rename fieldC as fieldB
| stats values(fieldA) AS fieldA (...) by fieldB

 

 

 

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...