Splunk Search

The Join command doesn't combine results from different indexes

jamercadoh
Explorer

The search string shown below returns valid results when run in Splunk 4.3.4 but it doesn't in Splunk 5.0.

index=agent MTRn |fields MTRn S| join S [search svc="*"| fields svc, sessionId Site | rename sessionId AS S]|table MTRn S Site

The result shows empty values for the "MTRn" column and the "S" and "site" columns show data from the subsearch.

Cheers,

Tags (1)
0 Karma

jamercadoh
Explorer

The sub-search searches data in the "main" index whereas the outer does it in the "agent" index. I tried to include the index=main clause to no avail.

0 Karma

Ron_Naken
Splunk Employee
Splunk Employee

Your inner search is an entirely separate and unrelated search from the outer search, so it needs to also include the index to search: ie:

index=agent MTRn |fields MTRn S| join S [search index=agent svc="*"| fields svc, sessionId Site | rename sessionId AS S]|table MTRn S Site
0 Karma

jamercadoh
Explorer

The sub-search searches data in the "main" index whereas the outer does it in the "agent" index. I tried to include the index=main clause to no avail.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...