single column join is working
index=* source=jar columns.path="*/log4j-core*" NOT columns.path=*/log4j*2.17* host IN (*.test.com)
| rename columns.pid AS pid, columns.pid_ts as pid_ts, columns.path as path,
| dedup host path pid
| join pid type=left max=1 [search index=* source=process host IN (*.test.com) earliest=-25h latest=now
| rename columns.pid AS pid, columns.cmdline as cmd, columns.username as user, columns.uid as uid, columns.groupname as group, columns.gid as gid
| dedup host pid]
| table host, path, pid, user, uid, group, gid, cmd
but multi column join is not working
index=* source=jar columns.path="*/log4j-core*" NOT columns.path=*/log4j*2.17* host IN (*.test.com)
| rename columns.pid AS pid, columns.pid_ts as pid_ts, columns.path as path,
| dedup host path pid
| join host,pid type=left max=1 [search index=* source=process host IN (*.test.com) earliest=-25h latest=now
| rename columns.pid AS pid, columns.cmdline as cmd, columns.username as user, columns.uid as uid, columns.groupname as group, columns.gid as gid
| dedup host pid]
| table host, path, pid, user, uid, group, gid, cmd
Splunk Enterprise
Version:8.2.6Build:a6fe1ee8894b
... View more