Splunk Search

Joing data from 2 data

SplunkBaby
Explorer

Hi

I want to join data from DB with an csv file data.
both DB and csv file have a common column which can be used for joining.
How can i achieve this?

Thanks

0 Karma

Ayn
Legend

First of all it sounds like you need to take the Splunk tutorial (http://docs.splunk.com/Documentation/Splunk/latest/SearchTutorial/WelcometotheSearchTutorial ). It equips you with the knowledge you need for knowing where to look for solutions. Secondly, the join command docs are here: http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Join

0 Karma

SplunkBaby
Explorer

I have only loaded 2 data source.I dont know how to join this.
Give me some tutorial links or description to join this.

0 Karma

Ayn
Legend

Where exactly are you running into problems? I guess you found the "join" command but ran into some kind of issues with it?

0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...