The **join** command combines the results of a main search with the results of a subsearch using one or more common fields.
By default, join performs an inner join: it only keeps results that exist in BOTH datasets.
Use `type=outer` to keep all results from the main search, even if they don't match the subsearch.
index=web | join clientip [ search index=security action=blocked ]