Splunk Search

Join on indexed value with a wildcard

Cuyose
Builder

I am trying to join on indexed data where I want to have something like 123 join with 123 and also 123-14XXx

Where 123 is variable. I can't seem to figure out what to use here, basically the logic is if there is a dash, strip it and everything after it off before attempting the join.

Any ideas?

Tags (3)
0 Karma

gkanapathy
Splunk Employee
Splunk Employee

You should probably use the "eval" or "rex" commands to create a new field with the subvalue you want, then join against that field.

Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...