Splunk Search

self join in splunk



Can you make me understand how to use a self join using splunk..

A short example will work.

thanks a lot !!


Tags (4)


....| selfjoin []* gives you a join on the selected field(s). The options are useful (overwrite, max or keepsingle. That allows control over values in the selected fields. Note the default on 'max' vs zero.
There's more at http://docs.splunk.com/Documentation/Splunk/5.0/SearchReference/Selfjoin

The example used is ... | selfjoin id...which may start you off with results. Depends what you are trying to do after that 😉

Get Updates on the Splunk Community!

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...