<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: why is my join not working here? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-is-my-join-not-working-here/m-p/649403#M224544</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/243242"&gt;@Woodpecker&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if you separately run the two searches, have congruent results (in term of field names and values)?&lt;/P&gt;&lt;P&gt;The stats command runs only if they are congruent.&lt;/P&gt;&lt;P&gt;About the time field, if you want only one value you have to transform it in epochtime (using strptime) and take one of them or, in the stats command, use first or last option to take one value.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Thu, 06 Jul 2023 07:04:40 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2023-07-06T07:04:40Z</dc:date>
    <item>
      <title>Why is my join not working here?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-my-join-not-working-here/m-p/649394#M224541</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;In my first search, I got all the details which needs to be displayed in the results but it doesn't have an IP field.. So, in my second search same index different category, has an IP fields and I try to join it using the user field.&lt;BR /&gt;&lt;BR /&gt;Both searches when run separately has results, but when using join it is not working.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;index=A category=Requiredevents
| rename required.user as user 
| fields user category identity time 
| join type=left user [| search index=A category=Requiredevents2 required.user=* required.ipaddress=*
| rename required.user as user required.ipaddress as ipaddress | fields user ipaddress]
| table user category identity time ipaddress&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I also tried using stats like this, but it didn't work&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;(index=A category=Requiredevents) OR (| search index=A category=Requiredevents2 )
| rename required.user as user required.ipaddress as ipaddress
| fields user category identity ipaddress time 
| stats count user category identity time ipaddress&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any help would be appreciated, thank you&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jul 2023 17:00:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-my-join-not-working-here/m-p/649394#M224541</guid>
      <dc:creator>Woodpecker</dc:creator>
      <dc:date>2023-07-07T17:00:22Z</dc:date>
    </item>
    <item>
      <title>Re: why is my join not working here?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-my-join-not-working-here/m-p/649397#M224542</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/243242"&gt;@Woodpecker&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;what do you mean with "it doesn't work"? no results, inconsistent results, what else?&lt;/P&gt;&lt;P&gt;Anyway, I don't see the join search because join is a solution to use only when there isn't any other solution and when you have very few events.&lt;/P&gt;&lt;P&gt;at first is "time" a field of your events or are you speaking of _time?&lt;/P&gt;&lt;P&gt;in both cases to put the timestamp in a BY clause of a stats command, you have to group values using bin or put it in the values choosing earliest or latest value&lt;/P&gt;&lt;P&gt;Then you cannot use "| search" in the main search.&lt;/P&gt;&lt;P&gt;At lease the searches thart you used in the join are different than the ones in the stats.&lt;/P&gt;&lt;P&gt;Then in the stats command you didin't group by user as in the join.&lt;/P&gt;&lt;P&gt;so see my approach and adapt it to your use case:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;(index=A category=Requiredevents) OR (index=A category=Requiredevents2 required.user=* required.ipaddress=*)
| rename required.user as user required.ipaddress as ipaddress
| stats 
   count 
   values(category) AS category 
   values(identity) AS identity
   earliest(_time) AS _time
   values(ipaddress) AS ipaddress BY user &lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2023 06:40:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-my-join-not-working-here/m-p/649397#M224542</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-07-06T06:40:45Z</dc:date>
    </item>
    <item>
      <title>Re: why is my join not working here?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-my-join-not-working-here/m-p/649401#M224543</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I meant the inconsistent results.&lt;BR /&gt;&lt;BR /&gt;I have all my required values from&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;index=A category=Requiredevents&lt;/PRE&gt;&lt;P&gt;ie., the user identity category time (time- is a field in my events)&lt;BR /&gt;&lt;BR /&gt;I just need the equivalent IP address from&lt;/P&gt;&lt;PRE&gt;index=A category=Requiredevents2 required.user=* required.ipaddress=*&lt;/PRE&gt;&lt;P&gt;So, I tried to perform a join using user to fetch only the IPaddress.. If I try with search proposed below I'm not seeing any values from category=Requiredvents instead I'm seeing all values- (user identity category)&amp;nbsp; from category=Requiredvents2&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2023 07:01:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-my-join-not-working-here/m-p/649401#M224543</guid>
      <dc:creator>Woodpecker</dc:creator>
      <dc:date>2023-07-06T07:01:54Z</dc:date>
    </item>
    <item>
      <title>Re: why is my join not working here?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-my-join-not-working-here/m-p/649403#M224544</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/243242"&gt;@Woodpecker&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if you separately run the two searches, have congruent results (in term of field names and values)?&lt;/P&gt;&lt;P&gt;The stats command runs only if they are congruent.&lt;/P&gt;&lt;P&gt;About the time field, if you want only one value you have to transform it in epochtime (using strptime) and take one of them or, in the stats command, use first or last option to take one value.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2023 07:04:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-my-join-not-working-here/m-p/649403#M224544</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-07-06T07:04:40Z</dc:date>
    </item>
    <item>
      <title>Re: why is my join not working here?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-my-join-not-working-here/m-p/649408#M224545</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;as&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;said you should avoid to use join if possible. Here is one post how you could replace those&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Splunk-Search/What-is-the-relation-between-the-Splunk-inner-left-join-and-the/m-p/391290/highlight/true#M113950" target="_blank"&gt;https://community.splunk.com/t5/Splunk-Search/What-is-the-relation-between-the-Splunk-inner-left-join-and-the/m-p/391290/highlight/true#M113950&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Also on .conf have kept lot of presentation how to avoid join. Here is link to one&amp;nbsp;&lt;A href="https://conf.splunk.com/files/2020/slides/TRU1761C.pdf" target="_blank"&gt;https://conf.splunk.com/files/2020/slides/TRU1761C.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2023 07:34:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-my-join-not-working-here/m-p/649408#M224545</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-07-06T07:34:00Z</dc:date>
    </item>
  </channel>
</rss>

