Splunk Search

Join by time range

stwong
Communicator

Hi all,

 

Possible to join 2 search results like following?

 

Set 1:

_time 

field1

field2

field3 (common field)

 

Set 2:

_time  

fieldA (multiple values, contains start/end time) 

fieldB 

field3 (common field)

 

Then join with common field3, together with:

 

fieldA (start) < _time (Set1) < fieldA (end)

 

Thanks a lot.

Regards

/stwong

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Rename _time in query 2 as part of the join, then you will be able to do your comparison / filter after the join

0 Karma

stwong
Communicator

Thanks.  Seems if join first with common field3,  unable to do filter afterwards. Would you advise how?  Sorry for the newbie question.

Thanks.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

@stwong I don't understand what you mean. Perhaps if you gave some concrete examples of your queries and data we might be able to help more.

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...