Splunk Search

Joint two table with subrow

alberttra
Engager

I' struggle with joining two following table:
Table1
alt text

Table 2
alt text

The row company of table 1 contains two industry_id, which I want to joint with the second table. The result should be like this:

`

ADIDAS AG | 194677F8-7774-4685-896D-9FB45E248245 | Sshwaz

| 4418BACC-BF07-452C-B3A7-BACBAD469FFD | Retail

DEUTSCHE LUFTHANSA AG

`

Is there anyway to get that result?

Tags (2)
0 Karma

to4kawa
Ultra Champion

please provide both queries.

0 Karma
Get Updates on the Splunk Community!

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...