<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Pass subsearch field to parent search in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Pass-subsearch-field-to-parent-search/m-p/500244#M139303</link>
    <description>&lt;P&gt;Try like this&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; index=*  [search index=* "idnumber" | tail 1 | table Number |eval Number=mvrange(Number-10,Number+10) ]
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Mon, 03 Feb 2020 22:35:21 GMT</pubDate>
    <dc:creator>somesoni2</dc:creator>
    <dc:date>2020-02-03T22:35:21Z</dc:date>
    <item>
      <title>Pass subsearch field to parent search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Pass-subsearch-field-to-parent-search/m-p/500243#M139302</link>
      <description>&lt;P&gt;I am trying to pass number from subsearch to main search  and find before or after 10 values of number. So if number is 50 parent search should pull events from 59 to 59 or 50 to 41.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=* Number="*" [search index=* "idnumber" | tail 1 | fields Number | format] | head/tail 10
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 03 Feb 2020 20:20:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Pass-subsearch-field-to-parent-search/m-p/500243#M139302</guid>
      <dc:creator>satya2p</dc:creator>
      <dc:date>2020-02-03T20:20:52Z</dc:date>
    </item>
    <item>
      <title>Re: Pass subsearch field to parent search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Pass-subsearch-field-to-parent-search/m-p/500244#M139303</link>
      <description>&lt;P&gt;Try like this&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; index=*  [search index=* "idnumber" | tail 1 | table Number |eval Number=mvrange(Number-10,Number+10) ]
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 03 Feb 2020 22:35:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Pass-subsearch-field-to-parent-search/m-p/500244#M139303</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2020-02-03T22:35:21Z</dc:date>
    </item>
    <item>
      <title>Re: Pass subsearch field to parent search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Pass-subsearch-field-to-parent-search/m-p/500245#M139304</link>
      <description>&lt;P&gt;Thank you, it worked.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2020 16:27:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Pass-subsearch-field-to-parent-search/m-p/500245#M139304</guid>
      <dc:creator>satya2p</dc:creator>
      <dc:date>2020-02-04T16:27:27Z</dc:date>
    </item>
  </channel>
</rss>

