Splunk Search

Replacing join command to integrate data from two different sources with lookups

ej56ygur
New Member

Hello people,

I am new in Splunk. So far I have been using join commands to integrate data from two different sources in a common field. The problem with this is that the searches take too long. apparently through lookups this should work faster. Would anybody be so kind to explain me exactly how I should do this ? it would be a massive thankyou from me.

Cheers

Tags (2)
0 Karma

woodcock
Esteemed Legend

Show us the search. How can we help otherwise?

0 Karma

dmarling
Builder

Can you provide some examples of the different queries that you need to join? Instead of doing things with join or lookups, you could use stats command on the field you were using to join. Lookups are fast, but require maintenance and can take up large amounts of disk space on your search head if you have an extremely large data set you are working with. Here's an extremely high level concept of using stats to combine data from different sources:

(search string 1) OR (string string 2)
| eval joiner=if(criteria unique to search string 1, field from search string 1 that you join on, field from search string 2 that you join on)
| stats values("Field from Search string 1") as "Field from Search string 1" values("Field from Search string 2") as "Field from Search string 2" by joiner
If this comment/answer was helpful, please up vote it. Thank you.
0 Karma

ej56ygur
New Member

First of all thank you so much for your answer Dustin. Tomorrow I will have the access to the code and will post it. than you so much

0 Karma

jodyfsu
Path Finder

If you have a common field in 2 different sources you may be able to crate an Alias for the fields.
https://docs.splunk.com/Documentation/Splunk/7.2.6/Knowledge/Addaliasestofields

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Mastering Threat Intelligence in ES 8.5, Splunk AI Assistant v2, and More from Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...