Hi
I've three tables with the following structure in the same Microsoft SQL database:
ApplicationEvent - Columns: id,application_id,message
Application - Columns: id,name, applicationtype_id
ApplicationType - Columns: id, name
I want to get the following row in SPLUNK:
ApplicationEvent.message, Application.name, ApplicationType.name
What's the best way to achieve this?
I've tried automatic lookups, lookup command and join without success.
Thanks in advance
Hi all
Thanks for your answers. I'll check this.
Why not create a 'view' on the database server that joins these tables. Then your dbconnect query is a simple select * from view_name
Hi jpass
thanks to you, too.
Yes best think to do, it's waste of resource to do that in splunk..
Have you considered joining them in SQL before indexing / loading into Splunk?