Splunk Search

Why does the index order change the amount of results returned by inner join and why are large amounts of data missing?

LWilliamson1
Explorer

Search:

index="A" |dedup Id | table Id | join max=0 type=inner Id [search index="B" ]| stats count(Id)

When switching index A & B, I receive more results, but it still doesn't match all of the Ids.
After checking both indexes and doing analysis on the Ids, it was found that over 6000 Ids didn't join, even though they existed in each data set.

0 Karma
1 Solution

s2_splunk
Splunk Employee
Splunk Employee

Are you hitting any of these default limits (from limits.conf), most likely, does your subsearch return more than 50000 events?
[join]
subsearch_maxout = 50000
subsearch_maxtime = 60
subsearch_timeout = 120

?

BTW, you also may want to remove the table Id or replace it with fields Id (unrelated, but more efficient).

View solution in original post

s2_splunk
Splunk Employee
Splunk Employee

Are you hitting any of these default limits (from limits.conf), most likely, does your subsearch return more than 50000 events?
[join]
subsearch_maxout = 50000
subsearch_maxtime = 60
subsearch_timeout = 120

?

BTW, you also may want to remove the table Id or replace it with fields Id (unrelated, but more efficient).

Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...