Splunk Search

join 3 queries

sarit_s
Communicator

Hello
I have 3 queries that i need to join between them but there is a catch 

query number 1 checks for users who sent sms
query number 2 checks if we tried to resend the sms

query number 3 check if we got verification that the sms sent

in the end - i want to see only the cases where we have sent, resend and verify - all of them by id
when im using simple join - i get all the results and not only those with the resend method 

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

It would help to know the specifics of each query.  Without them, the best I can do is

<<query number 1>>
| append [ <<query number 2>> ]
| append [ <<query number 3>> ]
| stats values(*) as * by id
---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

New Release | Splunk Cloud Platform 10.1.2507

Hello Splunk Community!We are thrilled to announce the General Availability of Splunk Cloud Platform 10.1.2507 ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

&#x1f5e3; You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...

Splunk New Course Releases for a Changing World

Every day, the world feels like it’s moving faster with new technological breakthroughs, AI innovation, and ...