Splunk Dev

subsearch join

sarit_s
Communicator

Hello

I have a field that does not return results when searching for specific string. 

i need to combine two searches so i will be able to return this field + other results from the search with the specific string

this is my query :

 

sourcetype=clientlogs OR sourcetype="client-logs-api" 
Categories="Login"
| stats count(eval( Message="Unable to load " OR Message="Unable to load from SDK")) as Faliure, values(Message) as Message values(IPAddress) as IPAddress, values(Url) as url by Country SessionGuid 

| appendpipe 
    [ stats sum(Faliure) as Faliure 
    | fillnull value=0 Faliure 
    | eval Country="TOTAL" ] 
| appendpipe 
    [ stats count(SessionGuid) as FailedSessions 
    | eval Country="TOTAL",Faliure="Faliure"] 
]
| table SessionGuid IPAddress Country Faliure Message FailedSessions url 
| sort - Faliure

 

i need to add the field CID which return no results when searching for the message at the beginning of the query 

how can i join them together so i will see in the table also the values of CID ?

Labels (1)
Tags (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

I am not sure I understand the requirement - do you want a list of CID where Categories != "Login" or a list of CID where message = "Unable to load " OR message = "Unable to load from SDK" or a list of CID where message != "Unable to load " AND message != "Unable to load from SDK" or something else?

0 Karma

sarit_s
Communicator

I want list of CID's when 

sourcetype=clientlogs OR sourcetype="client-logs-api"

and add it to the table

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| append [search sourcetype=clientlogs OR sourcetype="client-logs-api"
| stats values(CID) as CID]
0 Karma

sarit_s
Communicator

CID still empty

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

So CID doesn't exist in these sourcetypes?

If it does, how would you list them?

0 Karma

sarit_s
Communicator

It does. 
if im searching only for those sourcetyps i can find CID

but when i append this search with the rest it returns empty

0 Karma
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...