Hello, I am trying to join two searches for see, same hash exists on the other index as well. Below is my search, the issue is every time I run a search for the same timelimit, I see different results. WHY? Basesearch: I've tried to combine results of three different hash fields into one (index=a sourcetype="a" (hash1=* OR hash2=* OR hash3=*))
| fields hash1, hash2, hash3
| table hash1, hash2, hash3
| eval hash=mvzip(mvzip('hash1','hash2',"|"),'hash3',"|")
| fields hash
| makemv hash delim="|"
| mvexpand hash From here, I've joined two indexes and both indexes have same field for hash files, so I'm attempting to join hash as the focus. Search seems to work fine join type=left hash
[| search (index=b sourcetype=b hashfile=*) OR (index=c sourcetype=c hashfile=*)
| fields hashfile, filename,index
| eval hash=hashfile] Both the search on running individually returns 2k+ results, whereas on combining it, I could see only 1 result in the stats table and on hitting run for the same time limit every time I see different file name WHYYY? Any help would be appreciated, thanks!
... View more