> ## Documentation Index
> Fetch the complete documentation index at: https://docs-xcor.paloaltonetworks.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Join records

> Learn about the join records processing rule in Palo Alto Networks Telemetry Pipeline.

export const entity_0 = "join records processing rule"

<Info>
  This information is for Palo Alto Networks Telemetry Pipeline, which is a standalone
  product separate from Palo Alto Networks Cortex XCOR.
</Info>

The join records [processing rule](/ingest/pipeline/processing-rules) combines values
from multiple records into an array of values within a single record.

<Note>
  To determine which values to combine, this rule checks the timestamp of each record,
  then combines values from records that occur within the same nanosecond. This timestamp
  is a piece of metadata that Palo Alto Networks Telemetry Pipeline assigns to all records that
  pass through a pipeline, and is unrelated to any keys within the record itself.
</Note>

## Configuration parameters

Use the parameters in this section to configure the {entity_0}. The
Palo Alto Networks Telemetry Pipeline web interface uses the items in the **Name** column to
describe these parameters. [Pipeline configuration files](/ingest/pipeline/v2/configure/config-files)
use the items in the **Key** column as YAML keys.

| Name | Key | Description | Default |
| - | - | - | - |
| **Source key** | `key` | Required. The key that contains values to join in an array. The resulting array will be assigned to a key with the same name. | *none* |
| **Skip records where the specified key is missing** checkbox | `skipMissing` | Indicates whether to modify the record if the key isn't found. | Not selected |
| **Comment** | `comment` | A custom note or description of the rule's function. This text is displayed next to the rule's name in the **Actions** list in the processing rules interface. | *none* |

## Example

Using the join records processing rule lets you restructure your telemetry data
by turning multiple standalone events into a combined array. For example, given
these sample logs:

```json theme={null}
{"log":{"user_id":3,"action":"purchase"}}
{"log":{"user_id":4,"action":"click"}}
{"log":{"user_id":1,"action":"view"}}
{"log":{"user_id":5,"action":"click"}}
{"log":{"user_id":2,"action":"click"}}
```

A processing rule with the **Source key** value `log` returns the following result:

```json theme={null}
{"log":[{"user_id":3,"action":"purchase"},{"user_id":4,"action":"click"},{"user_id":1,"action":"view"}]}
{"log":[{"user_id":5,"action":"click"},{"user_id":2,"action":"click"}]}
```

This rule combined the `log` key from multiple standalone records into a series
of unified `log` arrays. Because the first three events occurred within the same
nanosecond, their `log` values were combined within one array, and because the
fourth and fifth events occurred one nanosecond later, their `log` values were
combined within another array.

## Related rules

For a processing rule with the opposite effect, see
[split record](/ingest/pipeline/processing-rules/split-record).


## Related topics

- [Split record](/ingest/pipeline/processing-rules/split-record.md)
- [Processing rules](/ingest/pipeline/processing-rules.md)
- [Multiline join](/ingest/pipeline/processing-rules/multiline-join.md)
- [Logging query syntax](/investigate/querying/query-logs/query-syntax.md)
- [Deduplicate records](/ingest/pipeline/processing-rules/deduplicate-records.md)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.