Hi Splunkers,
I struggled badly trying to get this solved, but no luck?
I need to join to a different search using the ip_address to get the host name :
Base search for the join: index= X&n...
Hello, How to join data from index and dbxquery without using JOIN, APPEND or stats command? Issue with JOIN: limit of subsearch 50,000 rows or fewer. Missing data. Issue with A...
Anything wrong with this join and subsearch? I know there are events which should match based on the 'cs_host' field. Not sure if the rename is confusing things, or my syntax is off slightly.
i...
I've read in other posts that using join in Splunk isn't great so I'm looking for a better way to do my search. I want a table of users connected to the company VPN, who are not using a corporate d...
I have 3 indexes that I need to join.
One index is the changes that we have in created in our Service Management tool. The second index is the Post Implementation Reviews (PIR's).&n...
Hi, I need to join data on my 2 source A and B on the fields "Workitems_URL" and "Work Item URL"
In source B, there is field "Type Name" that all of its join match must have this field c...
...-----------|---------------2-------------|-----------post---------- |--------xx----------
It means if I get 4 row data in first search, then after join, I need show 8 row data
Forgive my poor English, c...
Hi All, I want to join two indexes and get a result. Search Query -1 index=Microsoft | eval Event_Date=mvindex('eventDateTime',0) | eval UPN=mvindex('userStates{}.userPrincipalName',0...