I want to get data from joining two indexes out of which one is summary index.
Summary Index has more than 500000 records
I have two fields Asset and Date in the summary index as well as in the other index.
I am planning to schedule a query that will check for any new asset in today's records and if it is a new, it will insert that record in the summary index.
I tried to do it by leftjoin but it works if I specify a particular value for the Asset.
Below is the query that works(ASSETNAME is the hard coded value)
index=I ASSETNAME earliest=-1d@d latest=now
|fields Asset Date
|join type=left Combo(index=summary ASSETNAME earliest=-1Y@Y latest=now|eval Asset1=Asset
|where isnull(Asset1)
The same query does not work if I remove the asset name and run it with all the records in the Summary Index.
It shows me null values in the column 'Asset1' for the assets that are there in the summary index.
I am not sure if it is because of the the limit of the records a subsearch can return.
Please suggest that if there is a better way of querying instead of using join.
I tried to do it by this way also but it is not showing me complete set of records.
(index=I earliest=-1d@d latest=now) OR (index=summary earliest=-1Y@Y latest=now)
Thanks for the reply. I tried it with append also but results are truncated to maxout of 50000.