Hi,
You should be able to get the same results without using join
(splunk_server=indexer* index=wsi_tax_summary sourcetype=stash capability=109* tax_year=2019 ein=* intuit_offeringid=*
partnerId!=*test* partnerId=*)
| timechart span=1d dc(intuit_tid) as 19attempts
| streamstats sum(19attempts) as 19attempts
| eval time=strftime(_time,"%m-%d")
| append
[ inputlookup TY18_Splunk_total_data.csv
| where capability="109X"
| stats sum(attempts) as 18attempts by _time
| streamstats sum(18attempts) as 18attempts
| eval time=strftime(strptime(_time,"%m/%d/%Y"), "%m-%d")
| fields time 18attempts]
| stats values(19attempts) AS TY19, values(18attempts) AS TY18 by time
Cheers, Keith
... View more