Splunk Search

help on join command which truncate events

jip31
Motivator

Hello

The join comamnd below truncate events because I have results if I execute the ode before the join command but I havent results if I execute the second part

Considering that my company dont want to increase the subsearch limit, which other solutions I can apply please??

 

| inputlookup lookup_patches
| search Standard_PC=1 AND StateName="Non-Compl" 
| search OSVersion="*" 
| search HOSTNAME=302013154
| join HOSTNAME 
    [| inputlookup lookup_fo_all 
    | fields SITE RESPONSIBLE_USER DEPARTMENT HOSTNAME BUILDING_CODE ROOM TYPE CATEGORY STATUS ] 
| stats last(SITE) as Site, last(BUILDING_CODE) as Building, last(ROOM) as Room, last(RESPONSIBLE_USER) as Responsible, last(DEPARTMENT) as Department, count by HOSTNAME FileName StateName OSVersion

 

Labels (1)
Tags (1)
0 Karma

manjunathmeti
SplunkTrust
SplunkTrust

hi @jip31,

You use lookup command:

| inputlookup lookup_patches where Standard_PC=1 StateName="Non-Compl" OSVersion="*" HOSTNAME=302013154
| lookup lookup_fo_all HOSTNAME OUTPUT SITE RESPONSIBLE_USER DEPARTMENT BUILDING_CODE ROOM TYPE CATEGORY STATUS
| stats last(SITE) as Site, last(BUILDING_CODE) as Building, last(ROOM) as Room, last(RESPONSIBLE_USER) as Responsible, last(DEPARTMENT) as Department, count by HOSTNAME FileName StateName OSVersion

 

If this reply helps you, an upvote/like would be appreciated.

0 Karma

jip31
Motivator

hi

I have done this but performances are very bad because I have more than 60000 devices....

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...