hi
i try to concatene 2 similar query
| join type=outer host [search earliest=-120d index=windows sourcetype=winregistry
key_path="\\registry\\machine\\software\\wow6432node\\XX\\master\\PatchLevel"
| stats first(data) as PatchLevel by host
]
| join type=outer host [search earliest=-120d index=windows sourcetype=winregistry
key_path="\\registry\\machine\\software\\wow6432node\\XX\\master\\WindowsVersion"
| stats first(data) as WindowsVersion by host
]
i m doing something like this but it doesnt works
| join type=outer host [search earliest=-120d index=windows sourcetype=winregistry
key_path="\\registry\\machine\\software\\wow6432node\\XX\\master\\PatchLevel"
OR
key_path="\\registry\\machine\\software\\wow6432node\\XX\\master\\WindowsVersion"
|stats first(data) as PatchLevel by host, first(data) as WindowsVersion by host]
Try like this
| join type=outer host [search earliest=-120d index=windows sourcetype=winregistry
key_path="\\registry\\machine\\software\\wow6432node\\XX\\master\\PatchLevel"
OR
key_path="\\registry\\machine\\software\\wow6432node\\XX\\master\\WindowsVersion"
| rex field=key_path "(?<type>\w+)$" | chart first(data) by host type]
Try like this
| join type=outer host [search earliest=-120d index=windows sourcetype=winregistry
key_path="\\registry\\machine\\software\\wow6432node\\XX\\master\\PatchLevel"
OR
key_path="\\registry\\machine\\software\\wow6432node\\XX\\master\\WindowsVersion"
| rex field=key_path "(?<type>\w+)$" | chart first(data) by host type]
Hi and thanks
it works for these 2 key path
BUT
I need to add o ne key and i done this
| join type=outer host [search earliest=-120d index=windows sourcetype=winregistry
key_path="\registry\machine\software\wow6432node\xx\master\PatchLevel"
OR
key_path="\registry\machine\software\wow6432node\xx\master\WindowsVersion"
OR
key_path="\registry\machine\software\microsoft\windows nt\currentversion\ReleaseId"
| rex field=key_path "(?
But i have no data for ReleaseID
Other questions :
what is the reason why you user "rex" and "chart"?
thanks
oh i found for the 3 key 😉
so just tell me please what is the reason why you user "rex" and "chart"?
thanks
@jip31,
Try something like this ..
| join type=outer host [search earliest=-120d index=windows sourcetype=winregistry
key_path="\\registry\\machine\\software\\wow6432node\\airbus\\master\\PatchLevel"
OR
key_path="\\registry\\machine\\software\\wow6432node\\airbus\\master\\WindowsVersion"
|stats first(data) as PatchLevel , first(data) as WindowsVersion by host,data]
hello
nobody for helping me please??
something like this??
join type=outer host [append [search earliest=-120d index=windows sourcetype=winregistry
key_path="\\registry\\machine\\software\\wow6432node\\xx\\master\\PatchLevel"
OR key_path="\\registry\\machine\\software\\wow6432node\\xx\\master\\WindowsVersion"
|stats first(data) as PatchLevel , first(data) as WindowsVersion by host,data
In fact my main question is To know how to use append with a jointure field (host in my example)?
it doesnt works
please modify the key like in your answer :
\registry\machine\software\wow6432node\*XX*\master\PatchLevel"