Splunk Search

How to 'join' two data sets but neither left join or inner join are suitable?

Hi everyone,

I've tried to answer this myself but no luck. I fear it might be so simple i'm overlooking it. I'm comfortable with left & inner join, however i'm trying to 'join' two data sets that share the same field names but completely different values.

spreadsheet one -

'Issue key' 'Aging' 'Status'
'DR-1004'         '3'             'In Analysis'
'DR-1007'         '2'              'New'

Spreadsheet two -

'Issue key' 'Aging' 'Status'
'IT-85'       '6'             'New'
'IT-86'               '7'             'New'

And i'd like my results to be -

'Issue key' 'Aging' 'Status'
'DR-1004'         '3'              'In Analysis'
'DR-1007'         '2'              'New'
'IT-85'       '6'             'New'
'IT-86'               '7'             'New'

Which command can I use to add the results of spreadsheet two underneath the results of spreadsheet one, without using a matching field?

Please note I am using .csv files rather than indexes or sourcetypes.

Thanks!

0 Karma
1 Solution

Thanks, Append is what I was looking for, however the above didn't work. I tweaked it slightly and now i'm getting results.

| append [inputlookup Todays-IT-Tickets.csv | search Status=New OR Status="In Analysis"]

Cheers!

View solution in original post

Thanks, Append is what I was looking for, however the above didn't work. I tweaked it slightly and now i'm getting results.

| append [inputlookup Todays-IT-Tickets.csv | search Status=New OR Status="In Analysis"]

Cheers!

View solution in original post

Motivator

Please don't forget to "Mark as Answer" if your question has been resolved.

Cheers,
Jacob
0 Karma

Champion

Try this!

(|inputcsv spreadsheet 1)|append [|(inputcsv spreadsheet 2)]

0 Karma