OK. There are several things which catch my eye right off the bat. hostname!="*.corp" Two things "wrong" here (I mean, the search will run but it will be terribly inefficient). 1. Inclusion is better than exclusion. Splunk searches events by search terms and only those pre-selected events are verified against field extractions. In other words, if you do hostname=foo Splunk will find all events where there is a "foo" anywhere and will check which of those has "foo" in place of the hostname field. If you do hostname!=foo Splunk has to check every single event to see if it contains "foo" and if it does, is it in the hostname spot or not. 2. Splunk indexes terms which come from splitting the input data on breakers (spaces, tabs and such). And keeps a lexicon of those terms with entries pointing to the events containing those terms. So if you're looking for "foo" or "foo*" Splunk can find in its lexicon all entries being "foo" or starting with "foo". If you do "*foo", there is no such magic. Splunk has to scan every single event to find this string. Another thing - eventstats is a relatively "heavy" command. I assume that since you're pulling data from some summary, you might have it already relatively well "compacted" but in a general case, be aware that it can be very memory-consuming since it needs to have whole result set to operate on. And probably the main culprit - join type=inner sat_host [ search index="its-*-*tec-app" sourcetype="*:*:agent:reports" source="D:\\*eData\\*Agent_*.csv" earliest=-1d latest=-1m" | rename "Machine Name" as sat_host | eval sat_host = upper(sat_host) | stats latest(IP) as IP latest(Version) as Version_*, latest("Last Update Received") as last_update_recieved by sat_host] 1. You can't just write "as Version_*". Wasn't it supposed to be "latest(Version_*) as Version_*" (wildcard on right side of AS is allowed only as a match to left-side one). 2. More importantly - join with a raw event search usually ends in tears. Join command is usually best avoided altogether. Sometimes it's ok with a predictably fast search (like a small tstats or inputlookup). It practically never ends well with an index search. Join has a lot of limitations (result count, execution time) so it can get silently finalized and produce wrong/incomplete results without you ever knowing it. 3. You're joining on sat_host field which obviously (if your results before the join really look like what you're showing from the csv dump) does not exist in your data. You're doing | stats latest(os) as os latest(Last_Status_time) As Last_Status_Time by sat_host Which leaves you with fields: - os - Last_Status_Time - sat_host so when you arrive at | eval sat_host=upper(replace(DeviceName, "\..*$", "")) there is no DeviceName field in your result set.
... View more