Hi there
i am looking to join information from 2 separate indexes but due to performance constraints i am not able to use join
As the 2 index are relatively big.
Quick example:
index_1
- user_id : ABC123
- COMPUTER : PC1234
index_2
- PC : PC1234
- PC_NAME : WORKSTATION_ABC
Expected end result
- user_id : ABC123
- COMPUTER : PC1234
- PC_NAME : WORKSTATION_ABC
Normally i would be doing a join, but i heard i should be heading towards using splunk stew
As a new splunk user, my mind is so set on normal sql that i cant wrap my head around it
Any suggestions on how to solve this ?
THanks!
Use stats
to join the two data sets.
index=index_1 OR index=index_2
| eval COMPUTER=coalesce(COMPUTER, PC)
| stats values(*) as * by COMPUTER
| table user_id COMPUTER PC_NAME