Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Why does the index order change the amount of results returned by inner join and why are large amounts of data missing?

$
0
0
Search: index="A" |dedup Id | table Id | join max=0 type=inner Id [search index="B" ]| stats count(Id) When switching index A & B, I receive more results, but it still doesn't match all of the Ids. After checking both indexes and doing analysis on the Ids, it was found that over 6000 Ids didn't join, even though they existed in each data set.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>