Splunk Search

Is there a more efficient method than using join to combine searches?

bigrichie90
Path Finder

I was just wondering what more efficient methods there are when combining searches than using | join. I always hear everyone telling me that joins are a last resort because they aren't the most efficient way to combine searches. Any thoughts?

Tags (3)
1 Solution

MuS
Legend

ppablo
Retired

@piebob recently had me start sending out weekly featured Answers posts internally to certain teams in Splunk. Your post on alternatives to join, append and subsearches was in the first set I featured ;D

Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...