would like find things which can not inner join, meaning left side and right side which no common things
how search things which do not belong to inner join?
Try SPlunk's | set diff
command
http://docs.splunk.com/Documentation/Splunk/6.4.2/SearchReference/Set
| set diff [search yoursearch1 | table somefield] [search yoursearch2 | table somefield]
Try SPlunk's | set diff
command
http://docs.splunk.com/Documentation/Splunk/6.4.2/SearchReference/Set
| set diff [search yoursearch1 | table somefield] [search yoursearch2 | table somefield]
search is very slow when using last 4 hours, parsing job runs at least 3 minutes and still running
source=/var/log/remote/192.168.1.1.log set diff [search "Built inbound" NOT "8.8.8.8" NOT "8.8.4.4" | rex field=_raw "Outside:(?\d+.\d+.\d+.\d+){0,3}" | rex field=_raw "Inside:(?\d+.\d+.\d+.\d+){0,3}"] [search "Built outbound" outsideip=* | rex field=_raw "Outside:(?\d+.\d+.\d+.\d+){0,3}" | rex field=_raw "Inside:(?\d+.\d+.\d+.\d+){0,3}"] | mvexpand destinationip2 | table destinationip2, sourceip2 | stats values(sourceip2) as sourceip2, count by destinationip2 | sort by count by desc | head 10
maybe, can you give us some example data, so that it will be easy to understand your issue..