Splunk Search

How to use join with data model?

prajesh
New Member

I have tried using join to detect the common field from lookup but i need not find the fields that are not present using data model query.

|inputlookup Denied_traffic.csv |  join type=inner All_Traffic.src[| tstats `summariesonly`  dc(All_Traffic.src) as src from datamodel=Network_Traffic where All_Traffic.src_zone=outside All_Traffic.app!=incomplete All_Traffic.action=dropped OR All_Traffic.action=blocked by All_Traffic.src]
0 Karma

somesoni2
Revered Legend

You can do this without join itself (and it'll be much efficient)

| tstats `summariesonly`  dc(All_Traffic.src) as src from datamodel=Network_Traffic where All_Traffic.src_zone=outside All_Traffic.app!=incomplete All_Traffic.action=dropped OR All_Traffic.action=blocked [|inputlookup Denied_traffic.csv | table fieldInLookup | rename fieldInLookup as "All_Traffic.src] by All_Traffic.src
0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...