Hi,
I'm trying to port some SQL queries we wrote to Splunk but whereas with SQL I can specify which columns to join whatever their names are I couldn't replicate that in Splunk.
Here's an attempt using aliases (rename didnt work either) :
sourcetype="call"
| join type=left callerID as userId
[search sourcetype="user"
| fields userId]
| table event_id callerID userId
Thanks !
Rename certainly works.
If you have two sources like this:
user, field1
foo, value2
and like this:
userId, field2
foo, value2
you can do a search like this:
sourcetype=st1 | rename user as userId | join userId [search sourcetype=st2]
to get this:
userId, field1, field2
foo, value1, value2