why is inner join not working , Both searches are giving results. | inputlookup ABCD.csv | eval CC=mvdedup(CC) | rename CC as "Company Code" | streamstats first(lastchecked) as scan_check | eval key=_key,is_solved=if(lastchecked>lastfound OR lastchecked == 1,1,0),solved=finding."-".is_solved."-".key,blacklisted=if(isnull(blfinding),0,1),scandate=strftime(lastfound,"%Y-%m-%d %H:%M:%S"),lastchecked=if(lastchecked==1,scan_check,lastchecked),lastchecked=strftime(lastchecked,"%Y-%m-%d %H:%M:%S") | fillnull value="N.A." Asset_Gruppe Scan-Company Scanner Scan-Location Location hostname "Company Code" | search (is_solved=1 OR is_solved=0) (severity=informational) blacklisted=0 Asset_Gruppe="*" Scan-Company="*" Location="*" Scanner="*" dns="*" pluginname="*" ip="*" scandate="***" "Company Code"="*" | rex field=scandate "(?<new_date>\A\d{4}-\d{2}-\d{2})" | sort 0 -new_date | eventstats first(new_date) as timeval | rex field=new_date "-(?<date_1>\d\d)-" | rex field=timeval "-(?<date_2>\d\d)-" | strcat finding "#" NessusHost sid hostid pluginid finding | where date_1=date_2 | fields dns ip lastchecked severity pluginid pluginname scandate Asset_Gruppe Location Scan-Company "Company Code" Scan-Location solved Scanner finding | rename dns as Hostname,ip as IP | join type=inner Hostname [|inputlookup device.csv | table Hostname]
... View more