How to sisntaksise SPL language can obtain an analogue query SQL?
Example SQL:
select tab1.field1, tab2.field1 from tab1, tab2
where tab1.key_id = tab2.key_id
Please read the section in the docs dedicated to this: http://docs.splunk.com/Documentation/Splunk/6.0.1/SearchReference/SQLtoSplunk