Splunk Search

Join by time range

stwong
Communicator

Hi all,

 

Possible to join 2 search results like following?

 

Set 1:

_time 

field1

field2

field3 (common field)

 

Set 2:

_time  

fieldA (multiple values, contains start/end time) 

fieldB 

field3 (common field)

 

Then join with common field3, together with:

 

fieldA (start) < _time (Set1) < fieldA (end)

 

Thanks a lot.

Regards

/stwong

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Rename _time in query 2 as part of the join, then you will be able to do your comparison / filter after the join

0 Karma

stwong
Communicator

Thanks.  Seems if join first with common field3,  unable to do filter afterwards. Would you advise how?  Sorry for the newbie question.

Thanks.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

@stwong I don't understand what you mean. Perhaps if you gave some concrete examples of your queries and data we might be able to help more.

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!