Splunk Search

Unable to Put Together Join Search

IRHM73
Motivator

Hi, I wonder whether someone may be able to help me please.

After reading the Splunk documentation I'm trying to put together a Join query with the following:

index="main" auditSource=*auth* auditType=LoginEntitlements detail.EmpRef=* 
  | rename detail.EmpRef AS REF
  |Join REF [Chris EI-GG]
  | stats count by REF

Where [Chris EI-GG] is the name of the saved search which I want to join to the above.

I've clearly done something wrong because I receive the error 'Unknown search command 'chris'.

Could someone perhaps explain to me please where I've gone wrong.

Many thanks and kind regards

Chris

Tags (1)
0 Karma
1 Solution

chanmi2
Path Finder

Hi, you may want to take a look at this answer
http://answers.splunk.com/answers/55715/joining-results-from-saved-searches.html
and try

join REF [| savedsearch "Chris EI-GG" ]

Hope this help

View solution in original post

chanmi2
Path Finder

Hi, you may want to take a look at this answer
http://answers.splunk.com/answers/55715/joining-results-from-saved-searches.html
and try

join REF [| savedsearch "Chris EI-GG" ]

Hope this help

IRHM73
Motivator

Hi @chanmi2, thank you once more for helping me out with this. It is greatly appreciated and works fine.

Kind regards

Chris

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...