<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Help on subsearch in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Help-on-subsearch/m-p/414458#M171887</link>
    <description>&lt;P&gt;Hi @jip31 , I recognize this query. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;  The join is case sensitive so if the data of the HOSTNAME has different case than the host in the other query it won't match.  This should fix that if that's the case:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index="X" sourcetype="Y" source="Z" EventCode=6008 
| dedup host 
| eval host=lower(host)
| table _time host EventCode 
| join type=left host 
    [ search index=master-data-lookups sourcetype=":view_splunk_assets" 
    | stats count by HOSTNAME SITE ROOM TOWN CLIENT_USER COUNTRY OS 
    | fields - count 
    | rename HOSTNAME as host
    | eval host=lower(host)] 
| table _time host COUNTRY TOWN SITE ROOM CLIENT_USER OS 
| sort -_time limit=10
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;If that works, I'll convert this to an answer.&lt;/P&gt;</description>
    <pubDate>Fri, 12 Apr 2019 13:32:21 GMT</pubDate>
    <dc:creator>dmarling</dc:creator>
    <dc:date>2019-04-12T13:32:21Z</dc:date>
    <item>
      <title>Help on subsearch</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-on-subsearch/m-p/414456#M171885</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;

&lt;P&gt;I use the search below&lt;BR /&gt;
it works fine..... BUT for some host, I cant catch the fields there is in the subsearch&lt;BR /&gt;
It's strange because if I execute the subsearch index=master-data-lookups sourcetype=":view_splunk_assets"  apart, I have results....&lt;BR /&gt;
So what is the problem please?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index="X" sourcetype="Y" source="Z"  EventCode=6008
| dedup host 
| table _time host EventCode 
| join type=left host 
    [ search index=master-data-lookups sourcetype=":view_splunk_assets" 
    | stats count by HOSTNAME SITE ROOM TOWN CLIENT_USER COUNTRY OS 
    | fields - count 
    | rename HOSTNAME as host] 
| table _time host COUNTRY TOWN SITE ROOM CLIENT_USER OS 
| sort -_time limit=10
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 30 Sep 2020 00:09:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-on-subsearch/m-p/414456#M171885</guid>
      <dc:creator>jip31</dc:creator>
      <dc:date>2020-09-30T00:09:04Z</dc:date>
    </item>
    <item>
      <title>Re: Help on subsearch</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-on-subsearch/m-p/414457#M171886</link>
      <description>&lt;P&gt;@jip31 I think the issue is you are performing left join here so it returns all host of the main search and only returns the host of subsearch which is common with the main search so for the host which is from the main search does not have fields of subsearch&lt;/P&gt;

&lt;P&gt;if you want all host with these fields remove type=left &lt;/P&gt;

&lt;P&gt;Hope it helps!&lt;/P&gt;</description>
      <pubDate>Fri, 12 Apr 2019 13:32:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-on-subsearch/m-p/414457#M171886</guid>
      <dc:creator>riddhichandaran</dc:creator>
      <dc:date>2019-04-12T13:32:08Z</dc:date>
    </item>
    <item>
      <title>Re: Help on subsearch</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-on-subsearch/m-p/414458#M171887</link>
      <description>&lt;P&gt;Hi @jip31 , I recognize this query. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;  The join is case sensitive so if the data of the HOSTNAME has different case than the host in the other query it won't match.  This should fix that if that's the case:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index="X" sourcetype="Y" source="Z" EventCode=6008 
| dedup host 
| eval host=lower(host)
| table _time host EventCode 
| join type=left host 
    [ search index=master-data-lookups sourcetype=":view_splunk_assets" 
    | stats count by HOSTNAME SITE ROOM TOWN CLIENT_USER COUNTRY OS 
    | fields - count 
    | rename HOSTNAME as host
    | eval host=lower(host)] 
| table _time host COUNTRY TOWN SITE ROOM CLIENT_USER OS 
| sort -_time limit=10
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;If that works, I'll convert this to an answer.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Apr 2019 13:32:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-on-subsearch/m-p/414458#M171887</guid>
      <dc:creator>dmarling</dc:creator>
      <dc:date>2019-04-12T13:32:21Z</dc:date>
    </item>
    <item>
      <title>Re: Help on subsearch</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-on-subsearch/m-p/414459#M171888</link>
      <description>&lt;P&gt;Give this a try&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;(index="X" sourcetype="Y" source="Z"  EventCode=6008) OR (ndex=master-data-lookups sourcetype=":view_splunk_assets" )
| eval host=coalesce(HOSTNAME,host)
| time=if(EventCode="6008",_time,null())
| stats values(sourcetype) as sts max(time) as _time values(SITE) as SITE values(ROOM) as ROOM values(TOWN) as TOWN values(CLIENT_USER) as CLIENT_USER values(COUNTRY) as COUNTRY) values(OS) as OS by host
| where NOT (mvcount(sts)=1 AND sts=":view_splunk_assets")
 | table _time host COUNTRY TOWN SITE ROOM CLIENT_USER OS 
 | sort -_time limit=10
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 12 Apr 2019 14:28:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-on-subsearch/m-p/414459#M171888</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2019-04-12T14:28:17Z</dc:date>
    </item>
    <item>
      <title>Re: Help on subsearch</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-on-subsearch/m-p/414460#M171889</link>
      <description>&lt;P&gt;hello it doesnt works and its not a case sensitive issue because all the host are uppercase...&lt;/P&gt;</description>
      <pubDate>Sat, 13 Apr 2019 09:27:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-on-subsearch/m-p/414460#M171889</guid>
      <dc:creator>jip31</dc:creator>
      <dc:date>2019-04-13T09:27:15Z</dc:date>
    </item>
    <item>
      <title>Re: Help on subsearch</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-on-subsearch/m-p/414461#M171890</link>
      <description>&lt;P&gt;hi&lt;BR /&gt;
with this, I have host match well&lt;BR /&gt;
BUT.....&lt;BR /&gt;
There is something wrong&lt;BR /&gt;
when I execute my search I have host which correspond to index="X" sourcetype="Y" source="Z"  EventCode=6008 even if for some of them the matching not works (reason why I have opened this topic &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;BR /&gt;
but if I delete type=left, these host doenst appear in the result&lt;BR /&gt;
normally the should appear and match with the csv table....&lt;BR /&gt;
I dont understand anything...&lt;/P&gt;</description>
      <pubDate>Sat, 13 Apr 2019 09:39:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-on-subsearch/m-p/414461#M171890</guid>
      <dc:creator>jip31</dc:creator>
      <dc:date>2019-04-13T09:39:59Z</dc:date>
    </item>
    <item>
      <title>Re: Help on subsearch</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-on-subsearch/m-p/414462#M171891</link>
      <description>&lt;P&gt;hi somesoni&lt;BR /&gt;
when I launch it it says "mismatch quote or parenthesis"&lt;/P&gt;</description>
      <pubDate>Sat, 13 Apr 2019 09:44:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-on-subsearch/m-p/414462#M171891</guid>
      <dc:creator>jip31</dc:creator>
      <dc:date>2019-04-13T09:44:31Z</dc:date>
    </item>
    <item>
      <title>Re: Help on subsearch</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-on-subsearch/m-p/414463#M171892</link>
      <description>&lt;P&gt;your request works, thanks, but it is very long... &lt;BR /&gt;
is it possible to accelerate it please?&lt;BR /&gt;
could you explain me why when I m doing &lt;CODE&gt;index="x" sourcetype=y source="z" EventCode=6008&lt;/CODE&gt; on a 30 days period I have 6 events so 6 hosts but when I m doing `index="x" sourcetype=y source="z" EventCode=6008 (Level=1 OR Level=2 OR Level=3)&lt;/P&gt;

&lt;P&gt;| dedup host &lt;BR /&gt;
| table _time host EventCode &lt;BR /&gt;
| join type=left host &lt;BR /&gt;
    [ search index=master-data-lookups sourcetype="view_splunk_assets" &lt;BR /&gt;
    | stats count by HOSTNAME SITE ROOM TOWN CLIENT_USER COUNTRY OS &lt;BR /&gt;
    | fields - count &lt;BR /&gt;
    | rename HOSTNAME as host] &lt;BR /&gt;
| table _time host COUNTRY TOWN SITE ROOM CLIENT_USER OS &lt;BR /&gt;
| sort -_time limit=10`&lt;/P&gt;

&lt;P&gt;I have also 6 events on the same period but only 3 events are matching with my CSV file?&lt;BR /&gt;
Last question : the host list I want to compare is in a csv file&lt;BR /&gt;
Do I just have to add &lt;CODE&gt;[| inputlookup host.csv]&lt;/CODE&gt;after &lt;CODE&gt;(index="X" sourcetype="Y" source="Z"  EventCode=6008) OR (ndex=master-data-lookups sourcetype=":view_splunk_assets" )??&lt;/CODE&gt;&lt;BR /&gt;
Thanks in advance&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 00:05:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-on-subsearch/m-p/414463#M171892</guid>
      <dc:creator>jip31</dc:creator>
      <dc:date>2020-09-30T00:05:47Z</dc:date>
    </item>
  </channel>
</rss>

