Splunk Search

Get full join result of two logs

foloyo1314
Engager

How to get full join result of the below two logs:
log1:
ID, value1
1,aaa
1,abc

log2:
ID, value2
1,X1
1,X4
When join the two logs with source=log1 join type=inner ID [search source=log2] , it will get results like
ID,value1,value2
1,aaa,X1
1,abc,X1
How can I get the full join of the two logs like:
ID,value1,value2
1,aaa,X1
1,abc,X1
1,aaa,X4
1,abc,X4
Thanks!

Tags (1)
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

You're probably looking for the max=0 option of the join command, enabling the re-use of a previously joined event for more joins. Note though, for large inputs this may yield huge result sets.

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

You're probably looking for the max=0 option of the join command, enabling the re-use of a previously joined event for more joins. Note though, for large inputs this may yield huge result sets.

martin_mueller
SplunkTrust
SplunkTrust

The question of how to get the full join was indeed solved by setting max=0. If you have a different problem not solved by this you should ask a separate question.

0 Karma

smolcj
Builder

😞 How this is solved?? even i am looking for same solution.. i have 3 joins in my query 😞 but appending max=0 didn't solve my issue 😞

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...