Splunk Search

Joing data from 2 data

SplunkBaby
Explorer

Hi

I want to join data from DB with an csv file data.
both DB and csv file have a common column which can be used for joining.
How can i achieve this?

Thanks

0 Karma

Ayn
Legend

First of all it sounds like you need to take the Splunk tutorial (http://docs.splunk.com/Documentation/Splunk/latest/SearchTutorial/WelcometotheSearchTutorial ). It equips you with the knowledge you need for knowing where to look for solutions. Secondly, the join command docs are here: http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Join

0 Karma

SplunkBaby
Explorer

I have only loaded 2 data source.I dont know how to join this.
Give me some tutorial links or description to join this.

0 Karma

Ayn
Legend

Where exactly are you running into problems? I guess you found the "join" command but ran into some kind of issues with it?

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...