<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk nested query in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-nested-query/m-p/680422#M55732</link>
    <description>&lt;P&gt;Try something like this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="abc" aws_appcode="123" logGroup="watch" region="us-east-1" (cwmessage.message = "*Notification(REQUESTED)*") OR (cwmessage.message = "*Notification(COMPLETED)*") OR (cwmessage.message = "*Notification(UPDATED)*")
| stats latest(eval(if(match('cwmessage.message',".*Notification\(REQUESTED\).*"),_time,null()))) as start_time latest(eval(if(match('cwmessage.message',".*Notification\(COMPLETED\).*"),_time,null()))) as cdx_time latest(eval(if(match('cwmessage.message',".*Notification\(UPDATED\).*"),_time,null()))) as upd_time by cwmessage.transId
| eval cdx=cdx_time-start_time, upd=upd_time-cdx_time
| table cwmessage.transId, cdx,upd&lt;/LI-CODE&gt;</description>
    <pubDate>Tue, 12 Mar 2024 17:08:27 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2024-03-12T17:08:27Z</dc:date>
    <item>
      <title>Splunk nested query</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-nested-query/m-p/680406#M55731</link>
      <description>&lt;LI-CODE lang="markup"&gt;index="abc" aws_appcode="123" logGroup="watch" region="us-east-1" (cwmessage.message = "*Notification(REQUESTED)*")
|stats latest(_time) as start_time by cwmessage.transId
|join cwmessage.transId
[search index="abc" aws_appcode="123" logGroup="watch" region="us-east-1" (cwmessage.message = "*Notification(COMPLETED)*")
|stats latest(_time) as cdx_time by cwmessage.transId ]
[search index="abc" aws_appcode="123" logGroup="watch" region="us-east-1" (cwmessage.message = "*Notification(UPDATeD)*")
|stats latest(_time) as upd_time by cwmessage.transId ]
|join cwmessage.transId
|eval cdx=cdx_time-start_time, upd=upd_time-cdx_time
|table cwmessage.transId, cdx,upd&lt;/LI-CODE&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;From above query I'm using index query in multiple times, i want to use it as base search and call that in all nested searches for the dashboard. Please help me.&lt;BR /&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2024 16:00:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-nested-query/m-p/680406#M55731</guid>
      <dc:creator>smorla</dc:creator>
      <dc:date>2024-03-12T16:00:13Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk nested query</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-nested-query/m-p/680422#M55732</link>
      <description>&lt;P&gt;Try something like this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index="abc" aws_appcode="123" logGroup="watch" region="us-east-1" (cwmessage.message = "*Notification(REQUESTED)*") OR (cwmessage.message = "*Notification(COMPLETED)*") OR (cwmessage.message = "*Notification(UPDATED)*")
| stats latest(eval(if(match('cwmessage.message',".*Notification\(REQUESTED\).*"),_time,null()))) as start_time latest(eval(if(match('cwmessage.message',".*Notification\(COMPLETED\).*"),_time,null()))) as cdx_time latest(eval(if(match('cwmessage.message',".*Notification\(UPDATED\).*"),_time,null()))) as upd_time by cwmessage.transId
| eval cdx=cdx_time-start_time, upd=upd_time-cdx_time
| table cwmessage.transId, cdx,upd&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 12 Mar 2024 17:08:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-nested-query/m-p/680422#M55732</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-03-12T17:08:27Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk nested query</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-nested-query/m-p/680425#M55733</link>
      <description>&lt;P&gt;Are you trying to reduce the number of joins in the query (a good goal) or use this query in multiple dashboard panels (or maybe both)?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2024 17:47:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-nested-query/m-p/680425#M55733</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-03-12T17:47:57Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk nested query</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-nested-query/m-p/680474#M55734</link>
      <description>&lt;P&gt;Okay will try. Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2024 02:33:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Splunk-nested-query/m-p/680474#M55734</guid>
      <dc:creator>smorla</dc:creator>
      <dc:date>2024-03-13T02:33:33Z</dc:date>
    </item>
  </channel>
</rss>

