I've got a few different tables, all csv, that provide different information.
The main events table includes a bunch of fields that reference those other tables ie title_id field will contain a number and in the title_id table the numbers match up to a specific text value.
I have a number of these types of fields with matching tables. Is this something where i can upload all of the tables and join them in splunk, telling it how to reference? or is it something where i need to join the data external to splunk and upload it?
My goal is that when i search for something the actual title appears instead of the title id.
Sorry, i'm very new to this and super appreciate any assistance.
Hi @friskyapple,
you can follow both the approaches:
It depends on the knoledge you have in Splunk or in DB. I do all in Splunk (sometimes also joinings of Excel files!)!
Anyway, in Splunk you can join all the data using different methods:.
Ciao.
Giuseppe
Hi @friskyapple,
you can follow both the approaches:
It depends on the knoledge you have in Splunk or in DB. I do all in Splunk (sometimes also joinings of Excel files!)!
Anyway, in Splunk you can join all the data using different methods:.
Ciao.
Giuseppe