Splunk Search

It is truncated subsearch. tstats command.

nasha430
Explorer

Hi.

I have one problem. It is truncated subsearch result.

 

 

 

index="test-index01" sourcetype="test_sourcetype" user="*" OR user_name="*"
| stats count(file_name) as file_cnt sum(save_cnt) as save_cnt by user 
        file_name bunit id name
| join type=left file_name user
    [ | tstats summariesonly=t earliest(test_datamodel.privacy_count) as 
        privacy_count FROM datamodel=datamodel WHERE "test_datamodel.user"="*" 
        BY test_datamodel.user test_datamodel.file_name
      | rename test_datamodel.user as user test_datamodel.file_name as 
        file_name]

 

 

 

search result alert : [subsearch]: Subsearch produced 1485715 results, truncating to maxout 500000.

too many (BY user file_name) results. It is searched privacy_count query by user file_name.

So I want to listen your advice.

I don't know that I have to see some manual. 

Thank you.

Labels (2)
0 Karma

nasha430
Explorer

Oh, I solve my situation

index="test-index01" sourcetype="test_sourcetype" user="*" OR user_name="*"
| stats count(file_name) as file_cnt sum(save_cnt) as save_cnt by user 
        file_name bunit id name
| join type=left file_name user
    [ | tstats summariesonly=t earliest(test_datamodel.privacy_count) as 
        privacy_count FROM datamodel=datamodel 
        WHERE "test_datamodel.user"="*" 
        BY test_datamodel.user test_datamodel.file_name
      | rename test_datamodel.user as user test_datamodel.file_name as 
        file_name
      | join type=inner file_name user
        [search index="test-index01" sourcetype="test_sourcetype" user="*" OR 
         user_name="*"
         | stats count by file_name user]
      | fields file_name user privacy_count]

Index=test-index01 is few data(<500). Datamodel=datamodel is many data(>500000).

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...