Splunk Search

"Join" on a lookup not returning everything

DBattisto
Communicator

Hello! I am troubleshooting a report, and I've cut it all down to the very basics with the following two snippets. Basically, 'join' with a csv is not returning expected results. This dataset between Sept-1 and Sept-2 has about 75,000 unique entries (but the base search with "value=374667" only has about 30!).

 

 

index="xxx" sourcetype="xxx" value="374667"
timeformat="%Y-%m-%d" earliest="2021-09-01" latest="2021-09-02"
| join value [inputlookup lookup.csv]
| dedup value
| chart count

 

 

The above query returns 0 (incorrect).

 

 

index="xxx" sourcetype="xxx" value="374667"
timeformat="%Y-%m-%d" earliest="2021-09-01" latest="2021-09-02"
| dedup value
| chart count

 

 

The above query returns 1 (expected).

Labels (2)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Have you tried a lookup instead of join with inputlookup?

Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...