Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How to join the same sourcetype - Basically inner join with same sourcetype with different type of search string and compare the value (IN) condition. )

$
0
0
I am using the below query to achieve IN condition in same source. Basically I am achieving how many Order has been confirmed from hold. I got what I need but is there a better way of doing in. In simple words SQL IN query from same table. sourcetype="sourcetype1*" "called with OrderId : * and OperationType : confirm*" | rex field=message "OrderId : (?.*?) and" | table OrderId | join type=inner OrderId [| search sourcetype="sourcetype1*" "called with OrderId :*, Type : mobile* and OperationType : hold" | rex field=message "OrderId : (?.*?,)" | table OrderId] |stats count by OrderId.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>