Splunk Search

Get full join result of two logs

foloyo1314
Engager

How to get full join result of the below two logs:
log1:
ID, value1
1,aaa
1,abc

log2:
ID, value2
1,X1
1,X4
When join the two logs with source=log1 join type=inner ID [search source=log2] , it will get results like
ID,value1,value2
1,aaa,X1
1,abc,X1
How can I get the full join of the two logs like:
ID,value1,value2
1,aaa,X1
1,abc,X1
1,aaa,X4
1,abc,X4
Thanks!

Tags (1)
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

You're probably looking for the max=0 option of the join command, enabling the re-use of a previously joined event for more joins. Note though, for large inputs this may yield huge result sets.

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

You're probably looking for the max=0 option of the join command, enabling the re-use of a previously joined event for more joins. Note though, for large inputs this may yield huge result sets.

martin_mueller
SplunkTrust
SplunkTrust

The question of how to get the full join was indeed solved by setting max=0. If you have a different problem not solved by this you should ask a separate question.

0 Karma

smolcj
Builder

😞 How this is solved?? even i am looking for same solution.. i have 3 joins in my query 😞 but appending max=0 didn't solve my issue 😞

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...