I was just wondering what more efficient methods there are when combining searches than using | join. I always hear everyone telling me that joins are a last resort because they aren't the most efficient way to combine searches. Any thoughts?
Hi bigrichie90,
have a look at this answer http://answers.splunk.com/answers/129424/how-to-compare-fields-over-multiple-sourcetypes-without-joi...
cheers, MuS
Hi bigrichie90,
have a look at this answer http://answers.splunk.com/answers/129424/how-to-compare-fields-over-multiple-sourcetypes-without-joi...
cheers, MuS
@piebob recently had me start sending out weekly featured Answers posts internally to certain teams in Splunk. Your post on alternatives to join, append and subsearches was in the first set I featured ;D