<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SubSearch is not getting the info in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/SubSearch-is-not-getting-the-info/m-p/683703#M114134</link>
    <description>&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;I'm trying to use the subsearch, but I'm not what I am doing wrong.&lt;/P&gt;&lt;P&gt;First the inner search is a list of account like this one.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=main sourcetype=vpacmanagement
|eval DateStamp3= strptime(DateStamp, "%Y-%m-%d %H:%M:%S")
| eval MemberName2 = split(TeamMember, "\\")
| eval Member2 = mvindex(MemberName2,1) | eval Member2=upper(Member2)
| where DateStamp3 &amp;gt; relative_time(now(), "-4d") AND like(Status, "%/%/%") AND Member2 = "ADMMICHAEL_HAYES3"
|dedup WONumber | rename Member2 as Member | fields Member&lt;/LI-CODE&gt;&lt;P&gt;I get one account, all ok so far. But using the search in an outer search.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=main sourcetype=vpacmanagement|join Member[search index=main sourcetype=vpacmanagement
|eval DateStamp3= strptime(DateStamp, "%Y-%m-%d %H:%M:%S")
| eval MemberName2 = split(TeamMember, "\\")
| eval Member2 = mvindex(MemberName2,1) | eval Member2=upper(Member2)
| where DateStamp3 &amp;gt; relative_time(now(), "-4d") AND like(Status, "%/%/%") AND Member2 = "ADMMICHAEL_HAYES3"
|dedup WONumber | rename Member2 as Member | fields Member]
| eval DateStamp2= strptime(DateStamp, "%Y-%m-%d %H:%M:%S")
| eval month = strftime(DateStamp2, "%m")
| eval year = strftime(DateStamp2, "%Y")
| eval GroupName = split(DomainGroup, "\\"), MemberName = split(TeamMember, "\\")
| eval Name = mvindex(GroupName,1), Member = mvindex(MemberName,1) | eval RequestType = upper(RequestType), Name = upper(Name), Member=upper(Member)
| where not like(Status, "%/%/%") and DateStamp2 &amp;gt; relative_time(now(), "-2d")
|dedup RequestType,DomainGroup, TeamMember
| fields WONumber, DateStamp, ResourceSteward, RequestType, Name, Member, Status
| table WONumber, DateStamp, ResourceSteward, RequestType, Name,Member, Status | sort DateStamp2&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you see I made some calculation and I'm using Member field as value to make the join, but still is not getting any account from the outer, and in fact the element exists in the outer search, does anyone knows what am I missing?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 09 Apr 2024 15:57:25 GMT</pubDate>
    <dc:creator>rockym5</dc:creator>
    <dc:date>2024-04-09T15:57:25Z</dc:date>
    <item>
      <title>SubSearch is not getting the info</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SubSearch-is-not-getting-the-info/m-p/683703#M114134</link>
      <description>&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;I'm trying to use the subsearch, but I'm not what I am doing wrong.&lt;/P&gt;&lt;P&gt;First the inner search is a list of account like this one.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=main sourcetype=vpacmanagement
|eval DateStamp3= strptime(DateStamp, "%Y-%m-%d %H:%M:%S")
| eval MemberName2 = split(TeamMember, "\\")
| eval Member2 = mvindex(MemberName2,1) | eval Member2=upper(Member2)
| where DateStamp3 &amp;gt; relative_time(now(), "-4d") AND like(Status, "%/%/%") AND Member2 = "ADMMICHAEL_HAYES3"
|dedup WONumber | rename Member2 as Member | fields Member&lt;/LI-CODE&gt;&lt;P&gt;I get one account, all ok so far. But using the search in an outer search.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=main sourcetype=vpacmanagement|join Member[search index=main sourcetype=vpacmanagement
|eval DateStamp3= strptime(DateStamp, "%Y-%m-%d %H:%M:%S")
| eval MemberName2 = split(TeamMember, "\\")
| eval Member2 = mvindex(MemberName2,1) | eval Member2=upper(Member2)
| where DateStamp3 &amp;gt; relative_time(now(), "-4d") AND like(Status, "%/%/%") AND Member2 = "ADMMICHAEL_HAYES3"
|dedup WONumber | rename Member2 as Member | fields Member]
| eval DateStamp2= strptime(DateStamp, "%Y-%m-%d %H:%M:%S")
| eval month = strftime(DateStamp2, "%m")
| eval year = strftime(DateStamp2, "%Y")
| eval GroupName = split(DomainGroup, "\\"), MemberName = split(TeamMember, "\\")
| eval Name = mvindex(GroupName,1), Member = mvindex(MemberName,1) | eval RequestType = upper(RequestType), Name = upper(Name), Member=upper(Member)
| where not like(Status, "%/%/%") and DateStamp2 &amp;gt; relative_time(now(), "-2d")
|dedup RequestType,DomainGroup, TeamMember
| fields WONumber, DateStamp, ResourceSteward, RequestType, Name, Member, Status
| table WONumber, DateStamp, ResourceSteward, RequestType, Name,Member, Status | sort DateStamp2&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you see I made some calculation and I'm using Member field as value to make the join, but still is not getting any account from the outer, and in fact the element exists in the outer search, does anyone knows what am I missing?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 15:57:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SubSearch-is-not-getting-the-info/m-p/683703#M114134</guid>
      <dc:creator>rockym5</dc:creator>
      <dc:date>2024-04-09T15:57:25Z</dc:date>
    </item>
    <item>
      <title>Re: SubSearch is not getting the info</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SubSearch-is-not-getting-the-info/m-p/683719#M114135</link>
      <description>&lt;P&gt;The subsearch derived the Member field from TeamMember so it would seem the main search, which uses the same index and sourcetype, would expect a field called "TeamMember" to come from the subsearch.&amp;nbsp; For a join to work properly, both sides must use the same field name(s).&amp;nbsp; This can be done using rename in the subsearch.&lt;/P&gt;&lt;P&gt;Run the subsearch by itself with &lt;FONT face="courier new,courier"&gt;| format&lt;/FONT&gt; appended to see what the subsearch turns into.&amp;nbsp; That resulting string, inserted into the main search, is what produces the final result set.&amp;nbsp; Adjust the subsearch (or the &lt;FONT face="courier new,courier"&gt;join&lt;/FONT&gt; command itself) appropriately to get the results you want.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 16:46:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SubSearch-is-not-getting-the-info/m-p/683719#M114135</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-04-09T16:46:06Z</dc:date>
    </item>
  </channel>
</rss>

