<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Join two indexes with two different time ranges in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Join-two-indexes-with-two-different-time-ranges/m-p/416366#M119841</link>
    <description>&lt;P&gt;Hi vrmandadi,&lt;BR /&gt;
ok, anyway there's no sense to use join and inputlookup because the lookup command is a special join!&lt;BR /&gt;
So if in your lookup there are three fields (host_name ipv4 platform) you have to adapt my search:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; index=main sourcetype=rf Severity=High
 | rename IP as ipv4 
 | lookup mylookup.csv ipv4 OUTPUT host_name platform 
 | rename "Detection Method" as "Detection_Method" 
 | rename " Insight" as "V_Insight" 
 | rename "Product Result" as "Product_Result" 
 | rename "Software OS" as "Software_OS" 
 | replace "" WITH "abc" IN "Software_OS" 
 | replace "" WITH "xyz" IN "V_Insight" 
 | replace "" WITH "abc" IN "Product_Result" 
 | eval time=strftime(_time,"%d/%m/%Y %H:%M:%S") 
 | eval node=abc
 | eval resource="Vulnerability" 
 | eval type="Vulnerability" 
 | eval severity=1 
 | eval description="The host : " . host_name. " with Source IP: ". ipv4. " has Severity:" .Severity. " Solution:" .V_Insight. " WITH VDM:" . Detection_Method." AT: ". time."with OS Type :" .platform
 | table description
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
    <pubDate>Tue, 30 Jul 2019 08:46:31 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2019-07-30T08:46:31Z</dc:date>
    <item>
      <title>Join two indexes with two different time ranges</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Join-two-indexes-with-two-different-time-ranges/m-p/416361#M119836</link>
      <description>&lt;P&gt;I am trying to join two indexes through a common field but has a different name in the indexes and want to run in different time ranges .The common field is the IPAddress which is ipv4 in search1 and IP in search2 .What is the fast approach for the search to run , is it by joining the indexes or using the search1 as inputlookup . Below are the searches&lt;/P&gt;

&lt;P&gt;Search 1 -  [timerange - previous month]&lt;BR /&gt;
index=main sourcetype=rf Severity=High| rename IP as ipv4 &lt;/P&gt;

&lt;P&gt;Search 2 -[timerange - 24 hrs]&lt;/P&gt;

&lt;P&gt;index=xyz &lt;/P&gt;

&lt;P&gt;Below is the join I am using.I am trying to match the IP and output the host_name , platform ,from search 2 .the timerange is previous month but the search 2 should run for last 24hrs&lt;/P&gt;

&lt;P&gt;index=main sourcetype=rf Severity=High earliest=-1mon@mon latest=@m&lt;BR /&gt;
| rename IP as ipv4 &lt;BR /&gt;
| join ipv4 [search index=xyz earliest=-24hrs ].&lt;BR /&gt;
| eval description="The host : " . host_name. " with Source IP: ". ipv4. " has Severity:" .Severity. " Solution:" .Insight. " WITH VDM:" . Method." AT: ". time."with OS Type :" .platform&lt;BR /&gt;
| table description&lt;/P&gt;

&lt;P&gt;This resulted in no results as the search in join has no data in previous month&lt;/P&gt;

&lt;P&gt;Thanks in advance &lt;/P&gt;</description>
      <pubDate>Mon, 29 Jul 2019 13:48:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Join-two-indexes-with-two-different-time-ranges/m-p/416361#M119836</guid>
      <dc:creator>vrmandadi</dc:creator>
      <dc:date>2019-07-29T13:48:23Z</dc:date>
    </item>
    <item>
      <title>Re: Join two indexes with two different time ranges</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Join-two-indexes-with-two-different-time-ranges/m-p/416362#M119837</link>
      <description>&lt;P&gt;Hi vrmandadi,&lt;BR /&gt;
join isn't a good command because it's very slow.&lt;BR /&gt;
So you could try something like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;(index=main sourcetype=rf Severity=High earliest=-2mon@mon latest=-mon@mon) OR (index=xyz earliest=-24h@h latest=now)
| eval ipv4=coalesce(IP,ipv4)
| stats values(host_name) AS host_name values(Severity) AS Severity values(insight) AS insight values(Method) AS Method earliest(_time) AS _time values(platform) AS platform BY ipv4
| eval description="The host : ".host_name." with Source IP: ". ipv4." has Severity:".Severity." Solution:".Insight." WITH VDM:". Method." AT: ". _time."with OS Type :" .platform
| table description
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Beware to the field names.&lt;BR /&gt;
Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jul 2019 14:11:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Join-two-indexes-with-two-different-time-ranges/m-p/416362#M119837</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2019-07-29T14:11:49Z</dc:date>
    </item>
    <item>
      <title>Re: Join two indexes with two different time ranges</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Join-two-indexes-with-two-different-time-ranges/m-p/416363#M119838</link>
      <description>&lt;P&gt;Hello &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt; &lt;BR /&gt;
Thank you for your response . How can I use the search 2 results  as an inputlookup?.&lt;/P&gt;

&lt;P&gt;The search 2 which is index=xyz |stats count by host_name ipv4 platform |fields host_name ipv4 platform |outputlookup mylookup.csv &lt;/P&gt;

&lt;P&gt;I am using the above search results into the main query like below&lt;BR /&gt;
index=main sourcetype=rf Severity=High&lt;BR /&gt;
| rename IP as ipv4 &lt;BR /&gt;
| join ipv4 &lt;BR /&gt;
    [| inputlookup mylookup.csv &lt;BR /&gt;
    | fields ipv4 IP host_name platform] &lt;BR /&gt;
| rename "Detection Method" as "Detection_Method" &lt;BR /&gt;
| rename " Insight" as "V_Insight" &lt;BR /&gt;
| rename "Product  Result" as "Product_Result" &lt;BR /&gt;
| rename "Software OS" as "Software_OS" &lt;BR /&gt;
| replace "" WITH "abc" IN "Software_OS" &lt;BR /&gt;
| replace "" WITH "xyz" IN "V_Insight" &lt;BR /&gt;
| replace "" WITH "abc" IN "Product_Result" &lt;BR /&gt;
| eval time=strftime(_time,"%d/%m/%Y %H:%M:%S") &lt;BR /&gt;
| eval node=abc&lt;BR /&gt;
| eval resource="Vulnerability" &lt;BR /&gt;
| eval type="Vulnerability" &lt;BR /&gt;
| eval severity=1 &lt;BR /&gt;
| eval description="The host : " . host_name. " with Source IP: ". ipv4. " has Severity:" .Severity. " Solution:" .V_Insight. " WITH VDM:" . Detection_Method." AT: ". time."with OS Type :" .platform&lt;BR /&gt;
| table description&lt;/P&gt;

&lt;P&gt;but the issue is that when I run the search for previous month time range I see no results as the lookup does not have any data in the last month&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 01:31:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Join-two-indexes-with-two-different-time-ranges/m-p/416363#M119838</guid>
      <dc:creator>vrmandadi</dc:creator>
      <dc:date>2020-09-30T01:31:34Z</dc:date>
    </item>
    <item>
      <title>Re: Join two indexes with two different time ranges</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Join-two-indexes-with-two-different-time-ranges/m-p/416364#M119839</link>
      <description>&lt;P&gt;Hi vrmandadi,&lt;BR /&gt;
instead | inputlookup use the lookup command that is like a join command:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=main sourcetype=rf Severity=High
| rename IP as ipv4 
| lookup mylookup.csv ipv4 OUTPUT IP host_name platform 
| rename "Detection Method" as "Detection_Method" 
| rename " Insight" as "V_Insight" 
| rename "Product Result" as "Product_Result" 
| rename "Software OS" as "Software_OS" 
| replace "" WITH "abc" IN "Software_OS" 
| replace "" WITH "xyz" IN "V_Insight" 
| replace "" WITH "abc" IN "Product_Result" 
| eval time=strftime(_time,"%d/%m/%Y %H:%M:%S") 
| eval node=abc
| eval resource="Vulnerability" 
| eval type="Vulnerability" 
| eval severity=1 
| eval description="The host : " . host_name. " with Source IP: ". ipv4. " has Severity:" .Severity. " Solution:" .V_Insight. " WITH VDM:" . Detection_Method." AT: ". time."with OS Type :" .platform
| table description
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jul 2019 15:18:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Join-two-indexes-with-two-different-time-ranges/m-p/416364#M119839</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2019-07-29T15:18:00Z</dc:date>
    </item>
    <item>
      <title>Re: Join two indexes with two different time ranges</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Join-two-indexes-with-two-different-time-ranges/m-p/416365#M119840</link>
      <description>&lt;P&gt;Hello Giuseppe ,&lt;/P&gt;

&lt;P&gt;The lookup file I am using is coming from the search below&lt;BR /&gt;
index=xyz |stats count by host_name ipv4 platform |fields host_name ipv4 platform |outputlookup mylookup.csv&lt;/P&gt;

&lt;P&gt;How to schedule this search to run everyday and use this results as lookup file .the search runs for previous month and the lookup should be the latest run of the search &lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 01:31:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Join-two-indexes-with-two-different-time-ranges/m-p/416365#M119840</guid>
      <dc:creator>vrmandadi</dc:creator>
      <dc:date>2020-09-30T01:31:42Z</dc:date>
    </item>
    <item>
      <title>Re: Join two indexes with two different time ranges</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Join-two-indexes-with-two-different-time-ranges/m-p/416366#M119841</link>
      <description>&lt;P&gt;Hi vrmandadi,&lt;BR /&gt;
ok, anyway there's no sense to use join and inputlookup because the lookup command is a special join!&lt;BR /&gt;
So if in your lookup there are three fields (host_name ipv4 platform) you have to adapt my search:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; index=main sourcetype=rf Severity=High
 | rename IP as ipv4 
 | lookup mylookup.csv ipv4 OUTPUT host_name platform 
 | rename "Detection Method" as "Detection_Method" 
 | rename " Insight" as "V_Insight" 
 | rename "Product Result" as "Product_Result" 
 | rename "Software OS" as "Software_OS" 
 | replace "" WITH "abc" IN "Software_OS" 
 | replace "" WITH "xyz" IN "V_Insight" 
 | replace "" WITH "abc" IN "Product_Result" 
 | eval time=strftime(_time,"%d/%m/%Y %H:%M:%S") 
 | eval node=abc
 | eval resource="Vulnerability" 
 | eval type="Vulnerability" 
 | eval severity=1 
 | eval description="The host : " . host_name. " with Source IP: ". ipv4. " has Severity:" .Severity. " Solution:" .V_Insight. " WITH VDM:" . Detection_Method." AT: ". time."with OS Type :" .platform
 | table description
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2019 08:46:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Join-two-indexes-with-two-different-time-ranges/m-p/416366#M119841</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2019-07-30T08:46:31Z</dc:date>
    </item>
    <item>
      <title>Re: Join two indexes with two different time ranges</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Join-two-indexes-with-two-different-time-ranges/m-p/416367#M119842</link>
      <description>&lt;P&gt;Hi vrmandadi,&lt;BR /&gt;
to schedure a search to insert values in a lookup, you have to create an alert and schedule it as you like.&lt;BR /&gt;
I suggest to analyze also summary indexes, that could be useful for you.&lt;BR /&gt;
Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2019 12:31:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Join-two-indexes-with-two-different-time-ranges/m-p/416367#M119842</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2019-07-31T12:31:49Z</dc:date>
    </item>
  </channel>
</rss>

