Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How do I apply leftouter join into two diffetent search

$
0
0
I needs to apply left outer join or NOT IN condition on two different search search 1 : index=abc host="*xxx*" sourcetype=access_combined_wcookie NOT (sessionId="-" OR isnull(sessionId)) method=GET uri_path="/x/y/z*" | rex field=uri "^(?:[^/\\n]*/){4}(?P\\d+)" | eval pk=sessionId+CTM | dedup pk | table pk Search 2: index=def sourcetype=referral_activity APPOINTMENT_BOOKING_BOOKED | eval pk =substr(session_id, 9)+ctm | table pk | join type=inner pk [search index=abc host="*xxx*" sourcetype=access_combined_wcookie NOT (sessionId="-" OR isnull(sessionId)) method=POST uri_path="/x/y/w*" | rex field=uri "^(?:[^/\\n]*/){4}(?P\\d+)" | eval pk=sessionId+CTM | dedup pk | table pk ] Expected results : Unique pk values from search 1 which is not present into search 2 results Please advise..

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>