# Elastic Vs Splunk - Query Feature comparison - Join, Pipe(|), Table, dedup, eval, chart, rex

**URL:** <https://discuss.elastic.co/t/elastic-vs-splunk-query-feature-comparison-join-pipe-table-dedup-eval-chart-rex/23552>\
**Category:** Elasticsearch\
**Created:** [May 5, 2015, 8:53am UTC](https://discuss.elastic.co/t/elastic-vs-splunk-query-feature-comparison-join-pipe-table-dedup-eval-chart-rex/23552 "2015-05-05T08:53:18Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![mgarg](https://avatars.discourse-cdn.com/v4/letter/m/838e76/32.png) [@mgarg](https://discuss.elastic.co/u/mgarg)\
**Post date:** [May 5, 2015, 8:53am UTC](https://discuss.elastic.co/t/elastic-vs-splunk-query-feature-comparison-join-pipe-table-dedup-eval-chart-rex/23552/1 "2015-05-05T08:53:18Z")

</div>

I have recently switched from Splunk to Elastic in a pursuit to explore  
open source platform for performing descriptive analytics on my log data.

Until now, based on a few elastic query tutorials, I found that the Elastic  
DSL is a bit less advanced in providing nicely packaged features that are  
there in Splunk. With splunk, I can do a lot of things which are difficult  
or nearly impossible for me at the moment to replicate. I am using nearly  
20+ features from Splunk which are not there in Elastic.

I am doing a feature-wise study to establish functional correspondence  
between the Splunk and Elastic, but I would appreciate if someone can help  
me out in replicating similar behavior. The features are:

1. Join - SQL like join
2. Pipe (I) - Feed subsearch output to next query
3. dedup - remove duplicate documents
4. eval - add new field in document in search-time
5. chart - a feature similar to stats
6. rex - a search-time field extractor.

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/ecf14f29-15b4-4c46-93d0-f97125e00c9f%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/ecf14f29-15b4-4c46-93d0-f97125e00c9f%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 5, 2015, 10:31pm UTC](https://discuss.elastic.co/t/elastic-vs-splunk-query-feature-comparison-join-pipe-table-dedup-eval-chart-rex/23552/2 "2015-05-05T22:31:55Z")

</div>

1 cannot be done as joins in nosql land are very difficult-to-impossible to  
do natively.  
2 there's no functionality around that at the moment.  
3 should happen automatically, ES will not create a new document (event) if  
it exists, so there must be some difference there.  
4 you can update existing documents and add fields if you want. Just not  
via Kibana.  
5 there are lots of charts in Kibana what do you mean exactly.  
6 Logstash does this but it's pre-search, there is nothing post search at  
this time.

On 5 May 2015 at 18:53, Mohit Garg [mohitgargk@gmail.com](mailto:mohitgargk@gmail.com) wrote:

> I have recently switched from Splunk to Elastic in a pursuit to explore  
> open source platform for performing descriptive analytics on my log data.
> 
> Until now, based on a few elastic query tutorials, I found that the  
> Elastic DSL is a bit less advanced in providing nicely packaged features  
> that are there in Splunk. With splunk, I can do a lot of things which are  
> difficult or nearly impossible for me at the moment to replicate. I am  
> using nearly 20+ features from Splunk which are not there in Elastic.
> 
> I am doing a feature-wise study to establish functional correspondence  
> between the Splunk and Elastic, but I would appreciate if someone can help  
> me out in replicating similar behavior. The features are:
> 
> 1. Join - SQL like join
> 2. Pipe (I) - Feed subsearch output to next query
> 3. dedup - remove duplicate documents
> 4. eval - add new field in document in search-time
> 5. chart - a feature similar to stats
> 6. rex - a search-time field extractor.
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/ecf14f29-15b4-4c46-93d0-f97125e00c9f%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/ecf14f29-15b4-4c46-93d0-f97125e00c9f%40googlegroups.com)  
> [https://groups.google.com/d/msgid/elasticsearch/ecf14f29-15b4-4c46-93d0-f97125e00c9f%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/ecf14f29-15b4-4c46-93d0-f97125e00c9f%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .  
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

## -- Please update your bookmarks! We moved to [https://discuss.elastic.co/](https://discuss.elastic.co/)

You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAEYi1X912%3DwvZp7VP1H%2BbURcf1KVkEgexaHc97DVS5k0o49%3DTQ%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAEYi1X912%3DwvZp7VP1H%2BbURcf1KVkEgexaHc97DVS5k0o49%3DTQ%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![nickd](https://avatars.discourse-cdn.com/v4/letter/n/898d66/32.png) [@nickd](https://discuss.elastic.co/u/nickd)\
**Post date:** [November 17, 2015, 11:19pm UTC](https://discuss.elastic.co/t/elastic-vs-splunk-query-feature-comparison-join-pipe-table-dedup-eval-chart-rex/23552/3 "2015-11-17T23:19:04Z")

</div>

I've found the same issue. While Logstash allows for powerful data manipulation at collection/index time, Kibana lacks the search time flexibility and power that Splunk has with regard to easy free form querying and exploration of data.

Would love to see someone build a powerful query DSL on top of Kibana to solve this problem.

Don't get me wrong - I'm a huge ELK fan. But while the ELK stack is fantastic for structured, well understood data, Splunk still has a major advantage with exploring unstructured or poorly understood data.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:37pm UTC](https://discuss.elastic.co/t/elastic-vs-splunk-query-feature-comparison-join-pipe-table-dedup-eval-chart-rex/23552/4 "2017-07-05T23:37:49Z")

</div>


