Splunk Search

help on join command which truncate events

jip31
Motivator

Hello

The join comamnd below truncate events because I have results if I execute the ode before the join command but I havent results if I execute the second part

Considering that my company dont want to increase the subsearch limit, which other solutions I can apply please??

 

| inputlookup lookup_patches
| search Standard_PC=1 AND StateName="Non-Compl" 
| search OSVersion="*" 
| search HOSTNAME=302013154
| join HOSTNAME 
    [| inputlookup lookup_fo_all 
    | fields SITE RESPONSIBLE_USER DEPARTMENT HOSTNAME BUILDING_CODE ROOM TYPE CATEGORY STATUS ] 
| stats last(SITE) as Site, last(BUILDING_CODE) as Building, last(ROOM) as Room, last(RESPONSIBLE_USER) as Responsible, last(DEPARTMENT) as Department, count by HOSTNAME FileName StateName OSVersion

 

Labels (1)
Tags (1)
0 Karma

manjunathmeti
Champion

hi @jip31,

You use lookup command:

| inputlookup lookup_patches where Standard_PC=1 StateName="Non-Compl" OSVersion="*" HOSTNAME=302013154
| lookup lookup_fo_all HOSTNAME OUTPUT SITE RESPONSIBLE_USER DEPARTMENT BUILDING_CODE ROOM TYPE CATEGORY STATUS
| stats last(SITE) as Site, last(BUILDING_CODE) as Building, last(ROOM) as Room, last(RESPONSIBLE_USER) as Responsible, last(DEPARTMENT) as Department, count by HOSTNAME FileName StateName OSVersion

 

If this reply helps you, an upvote/like would be appreciated.

0 Karma

jip31
Motivator

hi

I have done this but performances are very bad because I have more than 60000 devices....

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...