<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic how to do a subsearch in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/how-to-do-a-subsearch/m-p/58321#M14255</link>
    <description>&lt;P&gt;I have the following query &lt;/P&gt;

&lt;P&gt;&lt;CLIENTNAME&gt; ((cdpbAbnamro:RunFiber "FileName" "ReportingResultId" ) OR ("reporting-process-manager:CreateReportingResult" "ProcessingTime"))&lt;/CLIENTNAME&gt;&lt;/P&gt;

&lt;P&gt;and the following is a result, for a particular run of a process it creates muiltiple such results as below depending on how many reports are present in the batch. So from the below  "bz9mf-37v-qgt" is the processID which is common in the two search resutls. I want to extract the FileName from one result and ProcessingTime from the other result&lt;/P&gt;

&lt;P&gt;bz9mf-37v-qgt  Filename Processingtime &lt;/P&gt;

&lt;P&gt;this should be my output can someone please help? &lt;/P&gt;

&lt;P&gt;1 » 12/7/12&lt;BR /&gt;
9:35:31.572 AM  2012-12-07 09:35:31,572 INFO  [cdpbAbnamro:RunFiber (120279:3011)] Deliverator.2106  (bz9mf-37v-qgt) (x-rmg-job:bz9mf-37p-uug#tag:2012-12-07:1354872928990) [Normal] bz9mf-37p-uug [Event/Other/ReportDetail] [DeliveryTime=2012-12-07 09:35:31.0, FileName=hfpositions.20121207.CreditExposure.5D, ReportingResultId=workflow@&lt;A href="mailto:abnamro.com@hfpositions.20121207.CreditExposure.5D"&gt;abnamro.com@hfpositions.20121207.CreditExposure.5D&lt;/A&gt;, Status=DELIVERED]&lt;/P&gt;

&lt;P&gt;2 » 12/7/12&lt;BR /&gt;
9:35:31.568 AM  2012-12-07 09:35:31,568 INFO  [reporting-process-manager:CreateReportingResult (140962:1398)] AuditFilter.1943   (bz9mf-37v-qgt) (x-rmg-job:bz9mf-37p-uug#tag:,2012-12-07:cdpbAbnamro,1354872929872) [Audit] End [Event/End/OperationEnd] [Action=urn:RiskMetricsDirect:1.0:reporting-process-manager:CreateReportingResult, CPU=20, IO=655, ProcessingTime=1501, ServiceTime=1492, Size=1360]&lt;/P&gt;</description>
    <pubDate>Mon, 10 Dec 2012 10:33:59 GMT</pubDate>
    <dc:creator>ashu_g50</dc:creator>
    <dc:date>2012-12-10T10:33:59Z</dc:date>
    <item>
      <title>how to do a subsearch</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-do-a-subsearch/m-p/58321#M14255</link>
      <description>&lt;P&gt;I have the following query &lt;/P&gt;

&lt;P&gt;&lt;CLIENTNAME&gt; ((cdpbAbnamro:RunFiber "FileName" "ReportingResultId" ) OR ("reporting-process-manager:CreateReportingResult" "ProcessingTime"))&lt;/CLIENTNAME&gt;&lt;/P&gt;

&lt;P&gt;and the following is a result, for a particular run of a process it creates muiltiple such results as below depending on how many reports are present in the batch. So from the below  "bz9mf-37v-qgt" is the processID which is common in the two search resutls. I want to extract the FileName from one result and ProcessingTime from the other result&lt;/P&gt;

&lt;P&gt;bz9mf-37v-qgt  Filename Processingtime &lt;/P&gt;

&lt;P&gt;this should be my output can someone please help? &lt;/P&gt;

&lt;P&gt;1 » 12/7/12&lt;BR /&gt;
9:35:31.572 AM  2012-12-07 09:35:31,572 INFO  [cdpbAbnamro:RunFiber (120279:3011)] Deliverator.2106  (bz9mf-37v-qgt) (x-rmg-job:bz9mf-37p-uug#tag:2012-12-07:1354872928990) [Normal] bz9mf-37p-uug [Event/Other/ReportDetail] [DeliveryTime=2012-12-07 09:35:31.0, FileName=hfpositions.20121207.CreditExposure.5D, ReportingResultId=workflow@&lt;A href="mailto:abnamro.com@hfpositions.20121207.CreditExposure.5D"&gt;abnamro.com@hfpositions.20121207.CreditExposure.5D&lt;/A&gt;, Status=DELIVERED]&lt;/P&gt;

&lt;P&gt;2 » 12/7/12&lt;BR /&gt;
9:35:31.568 AM  2012-12-07 09:35:31,568 INFO  [reporting-process-manager:CreateReportingResult (140962:1398)] AuditFilter.1943   (bz9mf-37v-qgt) (x-rmg-job:bz9mf-37p-uug#tag:,2012-12-07:cdpbAbnamro,1354872929872) [Audit] End [Event/End/OperationEnd] [Action=urn:RiskMetricsDirect:1.0:reporting-process-manager:CreateReportingResult, CPU=20, IO=655, ProcessingTime=1501, ServiceTime=1492, Size=1360]&lt;/P&gt;</description>
      <pubDate>Mon, 10 Dec 2012 10:33:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-do-a-subsearch/m-p/58321#M14255</guid>
      <dc:creator>ashu_g50</dc:creator>
      <dc:date>2012-12-10T10:33:59Z</dc:date>
    </item>
    <item>
      <title>Re: how to do a subsearch</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-do-a-subsearch/m-p/58322#M14256</link>
      <description>&lt;P&gt;Have you extracted the relevant fields (processId, Filename, Processingtime)? I'm not sure why you'd particularly want to use a subsearch for solving this.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Dec 2012 10:45:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-do-a-subsearch/m-p/58322#M14256</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2012-12-10T10:45:51Z</dc:date>
    </item>
    <item>
      <title>Re: how to do a subsearch</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-do-a-subsearch/m-p/58323#M14257</link>
      <description>&lt;P&gt;yes I have extracted these fields but as I said I want to join the two results based on the processid, as I asid its not just these two rows , for a client there are many rows (two each for a particular processID) depending on number or reports so &lt;/P&gt;

&lt;P&gt;basically output in a single row would be &lt;/P&gt;

&lt;P&gt;Process ID1    Processingtime1 &lt;BR /&gt;
Process ID1                     filename1&lt;/P&gt;

&lt;P&gt;Process ID2    Processingtime2&lt;BR /&gt;
Process ID2                     filename2&lt;BR /&gt;
..&lt;/P&gt;

&lt;P&gt;lets say there are 12 rows in actual result, I want to reduce to 6 &lt;BR /&gt;
Process ID1    Processingtime1  filename1&lt;BR /&gt;
Process ID2    Processingtime2  filename2&lt;/P&gt;</description>
      <pubDate>Mon, 10 Dec 2012 10:54:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-do-a-subsearch/m-p/58323#M14257</guid>
      <dc:creator>ashu_g50</dc:creator>
      <dc:date>2012-12-10T10:54:08Z</dc:date>
    </item>
    <item>
      <title>Re: how to do a subsearch</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-do-a-subsearch/m-p/58324#M14258</link>
      <description>&lt;P&gt;I think you could just use &lt;CODE&gt;stats&lt;/CODE&gt;.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | stats first(Filename) as Filename, first(Processingtime) as Processingtime by processID
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 10 Dec 2012 11:01:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-do-a-subsearch/m-p/58324#M14258</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2012-12-10T11:01:36Z</dc:date>
    </item>
    <item>
      <title>Re: how to do a subsearch</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-to-do-a-subsearch/m-p/58325#M14259</link>
      <description>&lt;P&gt;Great Worked fine!!! thanks&lt;/P&gt;</description>
      <pubDate>Mon, 10 Dec 2012 11:05:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-to-do-a-subsearch/m-p/58325#M14259</guid>
      <dc:creator>ashu_g50</dc:creator>
      <dc:date>2012-12-10T11:05:31Z</dc:date>
    </item>
  </channel>
</rss>

