Splunk Search

Adding a column from a subsearch

hatbeard
Explorer

I have this query that i've lightly changed from the winfra app, but i want to add a PID into it, that would be in the second query. I'm having trouble figuring out how to get this done.

eventtype="perfmon_windows" (Host="SERVER" ) Host="*" object="Process" counter="% Processor Time" instance="coldfusion*" AND NOT instance="coldfusions*"  | stats sparkline(avg(Value)) as Trend avg(Value) as Average, max(Value) as Peak, latest(Value) as Current, latest(_time) as "Last Updated" by instance | convert ctime("Last Updated") | sort - Current | eval Average=round(Average, 2) | eval Peak=round(Peak, 2) | eval Current=round(Current, 2)

then there's this one, which has the value of the PID

eventtype="perfmon_windows" (Host="SERVER" ) object="Process" instance="coldfusion*" AND NOT instance="coldfusions*"  counter="ID Process" |table Value

When I use a JOIN i get far too many columns back.

0 Karma

kamal_jagga
Contributor

There should be 1 field common in both the queries to combine the values.

Your first query doesn't have "value" field being carried in the final results.

Example:
| inputlookup abc.csv
| table common_field host
| appendcols
[| inputlookup xyz.csv
| table common_field dest
]
| table common_field host dest

hatbeard
Explorer

The instance field is common between them. They're similar searches, just on different objects.

0 Karma

kamal_jagga
Contributor

Following should work.
Example:
Search 1
| table instance *
| appendcols
[|Search 2
| table instance PID
]
| table instance PID *

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...