Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Replace join with stats to merge events based on common field

$
0
0
My datasets are much larger but these represent the crux of my hurdle sourcetype=sale_by fields: sid, user sourcetype=sale_made fields: sid, amount Where: `sale_made.sid = sale_by.sid` I have this search that works: sourcetype=sale_by | join sid [ search sourcetype=sale_made ] | stats sum(amount) by user Can this be done more efficiently with stats?

Viewing all articles
Browse latest Browse all 47296

Trending Articles