Why is the Splunk Web service not running after an upgrade to 6.2? Learn more »
How can I join two table in Splunk using query like this?
select dialog.id, dialog.callId, dialogParty_dialog_id, attributeKey_id, attributeValue
from dialog, descriptionsattribute
where callid = 'AL_a8wKVUUuX2qY7DgmBIg..' and dialog.id = dialogParty_dialog_id;"
thank you and regards,
What do you mean by "table"? Splunk doesn't have tables. It does have join and similar operators though, but it's often not a 100% good idea to try to implement the exact same concepts to Splunk searches as with SQL searches. That said, this "Splunk for SQL users" guide should prove useful.
Combining two search stats 1 Answer
Right join in Splunk 2 Answers
join searches using fuzzy time 0 Answers
Join search with multi-values 2 Answers