Splunk Search

How to join data from two indexes

poojak2579
Path Finder

I want to get data from joining two indexes out of which one is summary index.
Summary Index has more than 500000 records
I have two fields Asset and Date in the summary index as well as in the other index.

I am planning to schedule a query that will check for any new asset in today's records and if it is a new, it will insert that record in the summary index.

I tried to do it by leftjoin but it works if I specify a particular value for the Asset.

Below is the query that works(ASSETNAME is the hard coded value)

index=I ASSETNAME earliest=-1d@d latest=now
|fields Asset Date
|join type=left Combo(index=summary ASSETNAME earliest=-1Y@Y latest=now|eval Asset1=Asset
|where isnull(Asset1)

The same query does not work if I remove the asset name and run it with all the records in the Summary Index.

It shows me null values in the column 'Asset1' for the assets that are there in the summary index.

I am not sure if it is because of the the limit of the records a subsearch can return.
Please suggest that if there is a better way of querying instead of using join.

I tried to do it by this way also but it is not showing me complete set of records.

(index=I earliest=-1d@d latest=now) OR (index=summary earliest=-1Y@Y latest=now)

Tags (1)
0 Karma

poojak2579
Path Finder

Thanks for the reply. I tried it with append also but results are truncated to maxout of 50000.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Data Management Digest – September 2026

    Welcome to the September 2026 edition of Data Management Digest! September brought a fresh wave of ...

Federated Search for CloudWatch Unified Data Store Is Generally Available

As organizations modernize their cloud environments, AWS workloads generate more security, operational, and ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...