I have two separate search queries which are working separately but when i am trying to get data by joining them its not giving me any result from second query. first query- index=ads sourcetype="sequel" | eval jobname="Job for p1" | rex field=_raw "schema:(?P<db>[^ ]+)" | rex field=_raw "table:(?P<tb>[^ ]+)" | rex field=_raw "s_total_count:(?P<cnts>[^ ]+)" | rex field=_raw "origin_cnt_date:(?P<dte>[\D]+[\d]+[ ][\d]+[:]+[\d]+[:]+[\d]+[ ][\D]+[\d]+)" | eval date= strptime(dte, "%a %B %d %H:%M:%S") | eval dates=strftime(date, "%Y-%m-%d") | fields db tb cnts dates jobname | where cnts>0 | table dates jobname db tb cnts second query- index=ads sourcetype="isosequel" | rex field=_raw "schema:(?P<db>[^ ]+)" | rex field=_raw "table:(?P<tb>[^ ]+)" | rex field=_raw "count:(?P<cnt>[^ ]+)" | eval jobname1="Job for p2" | stats sum(cnt) as tb_cnt by jobname1 db tb | fields jobname1 db tb tb_cnt |table jobname1 db tb tb_cnt joined query(not working as expected)- index=ads sourcetype="sequel" | eval jobname="Job for p1" | rex field=_raw "schema:(?P<db>[^ ]+)" | rex field=_raw "table:(?P<tb>[^ ]+)" | rex field=_raw "s_total_count:(?P<cnts>[^ ]+)" | rex field=_raw "origin_cnt_date:(?P<dte>[\D]+[\d]+[ ][\d]+[:]+[\d]+[:]+[\d]+[ ][\D]+[\d]+)" | eval date= strptime(dte, "%a %B %d %H:%M:%S") | eval dates=strftime(date, "%Y-%m-%d") | fields db, tb, cnts, dates, jobname | join type=inner db tb [ search(index=ads sourcetype="isosequel") | rex field=_raw "schema:(?P<db>[^ ]+)" | rex field=_raw "table:(?P<tb>[^ ]+)" | rex field=_raw "count:(?P<cnt>[^ ]+)" | rex field=_raw "jobname:Job for (?P<jb>[a-z_A-Z0-9]+)" | stats sum(cnt) as tb_cnt by jb db tb | fields db, tb, tb_cnt, jb] | eval diff = cnts-tb_cnt | table dates, jobname, jb, db, tb, cnts, tb_cnt, diff requirement- I want to compare each db ,table with the second query db, table and get the difference, but i am not getting any result out of second query. any help would be appreciated !!! Thankyou in Advance !!
... View more