Splunk Search

Join on indexed value with a wildcard

Cuyose
Builder

I am trying to join on indexed data where I want to have something like 123 join with 123 and also 123-14XXx

Where 123 is variable. I can't seem to figure out what to use here, basically the logic is if there is a dash, strip it and everything after it off before attempting the join.

Any ideas?

Tags (3)
0 Karma

gkanapathy
Splunk Employee
Splunk Employee

You should probably use the "eval" or "rex" commands to create a new field with the subvalue you want, then join against that field.

Get Updates on the Splunk Community!

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...