Splunk Search

How to join metric data

drezanka
Explorer

I have several types of metric data going into a metric index. One has 'username' and 'DimA' as dimensions, and 'ValueA' as the metric_name.
The second type of metric data has 'DimA' as its dimension and 'ValueB' as the metric_name.
I would like to associate the 'username' with 'ValueB'.

How can I accomplish this?

0 Karma

somesoni2
Revered Legend

You should be able to run join after running mstats command like this
https://answers.splunk.com/answers/592935/using-mstats-to-create-separate-columns-per-metric-1.html

OR you can use append-stats alternative of join.

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...