Getting Data In

Selective join

sreelesh_n
New Member

Trying out for below

1) sourcetype="A" has login details
2) sourcetype ="B" has success login details

When I select a list box/check box on failures, I want to show a list joining both details where a record is present in the success table.
If I select All, It should show just details from the user table. (more like outer join here)

0 Karma

somesoni2
Revered Legend

Something like this might work (without join, have not seen your current query)

sourcetype="A" OR sourcetype="B" ..other base search | stats values(sourcetype) as sourcetype values(field1) as field1 values(field2) as field2 ... by common_field

Set following conditions based on checkbox selection

to show only items present in both

 | where mvcount(sourcetype)=2

To show all

 | where mvcount(sourcetype)>0
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...