- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Help with union not working
sarit_s
Communicator
06-16-2022
01:41 AM
Hello
I'm running this query:
| union
[ search host="puppet-01" OR host="jenkins-01" OR host="ANSIBLE-01" sourcetype=ProductionDeploy NOT Permisson_Job_Name=*_permission Environment=PRODUCTION
| table _time, App_Name, User, Change_Log_Description, Environment, Version]
[ search sourcetype=mscs:storage:blob:json
| rex field=_raw "Details\":\"(?<Details>.*?)\","
| rex field=_raw "ProjectName\":\"(?<ProjectName>.*?)\","
| rex field=_raw "ScopeDisplayName\":\"(?<ScopeDisplayName>.*?)\","
| rex field=_raw "releaseName\":\"(?<releaseName>.*?)\"}"
| rex field=_raw "ActionId\":\"(?<ActionId>Release.ReleaseCreated)\","
| rex field=_raw "ActorUPN\":\"(?<ActorUPN>.*?)\","
| rex field=_raw "DeploymentResult\":\"(?<DeploymentResult>.*?)\","
| rex field=_raw "PipelineName\":\"(?<PipelineName>.*?)\","
| where releaseName != null AND PipelineName like "%Production"
| rename ProjectName AS App_Name
| rename ActorUPN AS User
| rename releaseName AS Change_Log_Description
| rename PipelineName AS Environment
| rename DeploymentResult AS status
| table _time, App_Name, User, Change_Log_Description, Environment, Version,status]
| sort -_time asc
and im trying to get the status
at the first search i don't have this value but i do have it at the second one
i don't see status column at my results.
can someone explain me why ?
thanks
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ITWhisperer

SplunkTrust
06-16-2022
04:38 AM
Try your where command like this
| where isnotnull(releaseName) AND PipelineName like "%Production"
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
sarit_s
Communicator
06-16-2022
04:44 AM
still the same
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ITWhisperer

SplunkTrust
06-16-2022
04:58 AM
Does this rex match your events?
| rex field=_raw "DeploymentResult\":\"(?<DeploymentResult>.*?)\","
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
sarit_s
Communicator
06-19-2022
12:55 AM
yes it does
the problem is the since i don't have the field status at the first search i don't get the results of the second one
maybe the union not fit here ?
