Splunk Search

How to join inner?

marceldera
Explorer

Inter join is not displaying any results.   the search works however, nothing is showing up on the screen

index = tenable | rename hostnames as host.name | table host.name | join type=inner host.name [search (index=assetpanda) | fields host.name] | table host.name

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @marceldera,

I suppose that you already checked that there are matching values!

Anyway, the problem is probably in the limit of 50,000 values of the subsearch.

So you need to limit the values of the subsearch or (better!) use a different approach!

please the approach and adpt it to your need:

index = tenable OR index=assetpanda
| eval hostname=coalesce(hostname,host.name)
| stats dc(index) AS index_count values(index) AS index BY hostname
| where index_count=2
| table hostname

in general, avoid to use fields with spaces or special chars as dot.

Ciao.

Giuseppe

Get Updates on the Splunk Community!

Splunk Enterprise Security: Your Command Center for PCI DSS Compliance

Every security professional knows the drill. The PCI DSS audit is approaching, and suddenly everyone's asking ...

Developer Spotlight with Guilhem Marchand

From Splunk Engineer to Founder: The Journey Behind TrackMe    After spending over 12 years working full time ...

Cisco Catalyst Center Meets Splunk ITSI: From 'Payments Are Down' to Root Cause in ...

The Problem: When Networks and Services Don't Talk Payment systems fail at a retail location. Customers are ...