Splunk Search

Missing data when joining two larger sourcetypes which have more than a lakh rows

yashaswinig2210
Engager

Hi @renjith_nair 

Im trying to join two tables which have a common field but its not giving complete data as the tables have more than a lakh rows .? Is there any other option rather than join to combine the two tables

Labels (1)
0 Karma

scelikok
Champion

@yashaswinig2210, if I get it right try below;

| inputlookup firstLookup | append [ |inputlookup secondLookup ] 
| stats values(field1) values(field2) by common_field
If this reply helps you an upvote is appreciated.

scelikok
Champion

Hi @yashaswinig2210, on most cases you can use stats rather than join.

Sample query;

| (index=first_index search_criteria_1) OR (index=second_index search_criteria_2)
| stats values(field1) values(field2) by common_field

You can get more information about join vs stats in below document.

https://docs.splunk.com/Documentation/Splunk/8.1.1/Search/Abouteventcorrelation

 

If this reply helps you, an upvote is appreciated.

If this reply helps you an upvote is appreciated.

yashaswinig2210
Engager

@scelikok 

it didnt work for my sourcetype , can use the same stats with lookups?

 

0 Karma
.conf21 Now Fully Virtual!
Register for FREE Today!

We've made .conf21 totally virtual and totally FREE! Our completely online experience will run from 10/19 through 10/20 with some additional events, too!