<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LEFT JOIN not working in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/LEFT-JOIN-not-working/m-p/301540#M90794</link>
    <description>&lt;P&gt;Is there a reason you wouldn't want to search for all the events in one search, then perform &lt;CODE&gt;eval&lt;/CODE&gt; as necessary to normalize field names, then use &lt;CODE&gt;stats&lt;/CODE&gt; to get the values you need grouped by &lt;CODE&gt;product_name&lt;/CODE&gt;?&lt;/P&gt;</description>
    <pubDate>Thu, 11 Jan 2018 18:59:51 GMT</pubDate>
    <dc:creator>micahkemp</dc:creator>
    <dc:date>2018-01-11T18:59:51Z</dc:date>
    <item>
      <title>LEFT JOIN not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/LEFT-JOIN-not-working/m-p/301537#M90791</link>
      <description>&lt;P&gt;The below left join identified by ** is what i am trying to join onto the search but it is not listing all product_names per machine.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;`GEN_ProductionWorkstations` 
| table machine 
| join type=left machine 
    [ search index=sccm sourcetype=otl_dbin_machineinfo host=opspk source=dbmon-dump:/otl_dbin_machineinfo ] 
| join type=left machine 
    [ search index=ad source=otl_addnsscan 
    | eval machine=lower(machine) 
    | rename data as IP, name as machine 
    | table machine, IP, User_Name0, Model0, lastRebootDaysAgo] 
**| join type=left machine 
    [ search index=sccm computername=* product_name=* 
    | search category!="Device Drivers, Configuration, and Utilities" 
    | eval machine=lower(computername) 
    | fields machine, product_name 
    | dedup machine, product_name 
    | table machine, product_name ]**
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The final table should list  machine, IP, User_Name0, Model0, lastRebootDaysAgo, product_name. I think the issue is that there can be many  product_names per machine but only one User_Name0 and IP per machine.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 17:36:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/LEFT-JOIN-not-working/m-p/301537#M90791</guid>
      <dc:creator>davidcraven02</dc:creator>
      <dc:date>2020-09-29T17:36:54Z</dc:date>
    </item>
    <item>
      <title>Re: LEFT JOIN not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/LEFT-JOIN-not-working/m-p/301538#M90792</link>
      <description>&lt;P&gt;This is almost certainly an instance where there's a better way to accomplish what you're looking for without using &lt;CODE&gt;join&lt;/CODE&gt;.  And looking at your search, the first &lt;CODE&gt;join&lt;/CODE&gt; search only returns the &lt;CODE&gt;machine&lt;/CODE&gt; value, which is what is being joined on, so I'm not convinced this accomplishes anything.&lt;/P&gt;

&lt;P&gt;Can you include sample events for each of the searches and indicate what you want the final result to look for?&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jan 2018 02:17:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/LEFT-JOIN-not-working/m-p/301538#M90792</guid>
      <dc:creator>micahkemp</dc:creator>
      <dc:date>2018-01-11T02:17:12Z</dc:date>
    </item>
    <item>
      <title>Re: LEFT JOIN not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/LEFT-JOIN-not-working/m-p/301539#M90793</link>
      <description>&lt;P&gt;I want the final output to look like this;&lt;/P&gt;

&lt;P&gt;machine | product_name&lt;BR /&gt;
nas01b   |Adobe AIR, Adobe Flash Player, Bloomberg Office Tools ....&lt;BR /&gt;
nas02b   |Adobe 3.2, Adobe Flash Player ....&lt;/P&gt;

&lt;P&gt;When I run the below query It displays the product_name in one row and several machines grouped under ProductName but it only include 69 results when there should me much more results. &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;`GEN_ProductionWorkstations` 
| table machine 
|join type=left machine[search index=sccm sourcetype=otl_dbin_machineinfo host=opspkhf03p source=dbmon-dump://otl_db_opsccmsql_sccm/otl_dbin_machineinfo
| eval machine=lower(Name0)
| rename Client0 as SCCMClient, Active0 as SCCMClientActive, Caption0 as OperatingSystem] 
  | join type=left machine 
      [ search index=ad source=otl_addnsscan 
      | eval machine=lower(machine) 
      | rename data as IP
  ] 
  | join type=left machine 
      [ search index=sccm 
      | search category!="Device Drivers, Configuration, and Utilities" 
      | eval machine=lower(computername) 
     ] 
         | stats values(machine) AS ProductName by product_name
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 11 Jan 2018 14:28:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/LEFT-JOIN-not-working/m-p/301539#M90793</guid>
      <dc:creator>davidcraven02</dc:creator>
      <dc:date>2018-01-11T14:28:37Z</dc:date>
    </item>
    <item>
      <title>Re: LEFT JOIN not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/LEFT-JOIN-not-working/m-p/301540#M90794</link>
      <description>&lt;P&gt;Is there a reason you wouldn't want to search for all the events in one search, then perform &lt;CODE&gt;eval&lt;/CODE&gt; as necessary to normalize field names, then use &lt;CODE&gt;stats&lt;/CODE&gt; to get the values you need grouped by &lt;CODE&gt;product_name&lt;/CODE&gt;?&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jan 2018 18:59:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/LEFT-JOIN-not-working/m-p/301540#M90794</guid>
      <dc:creator>micahkemp</dc:creator>
      <dc:date>2018-01-11T18:59:51Z</dc:date>
    </item>
    <item>
      <title>Re: LEFT JOIN not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/LEFT-JOIN-not-working/m-p/301541#M90795</link>
      <description>&lt;P&gt;That sound like a good idea. How would I do this? Are you able to tweak my query? &lt;/P&gt;</description>
      <pubDate>Thu, 11 Jan 2018 19:03:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/LEFT-JOIN-not-working/m-p/301541#M90795</guid>
      <dc:creator>davidcraven02</dc:creator>
      <dc:date>2018-01-11T19:03:23Z</dc:date>
    </item>
    <item>
      <title>Re: LEFT JOIN not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/LEFT-JOIN-not-working/m-p/301542#M90796</link>
      <description>&lt;P&gt;It's tough to do without knowing what your initial macro expands to.  Can you expand that, and also show sample events from each index/sourcetype/whatever and note how they are related to each other.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jan 2018 19:04:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/LEFT-JOIN-not-working/m-p/301542#M90796</guid>
      <dc:creator>micahkemp</dc:creator>
      <dc:date>2018-01-11T19:04:36Z</dc:date>
    </item>
  </channel>
</rss>

