<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Filter search by subsearch values in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Filter-search-by-subsearch-values/m-p/535747#M151424</link>
    <description>&lt;P&gt;There's no much to work with in the question, but perhaps this gives you an idea.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;events to filter against subsearch ids&amp;gt; [search subsearch | return 1000 subsearch_id]&lt;/LI-CODE&gt;&lt;P&gt;The subsearch with &lt;FONT face="courier new,courier"&gt;return&lt;/FONT&gt; command returns a string of the type "&lt;FONT face="courier new,courier"&gt;(subsearch_id="foo" OR subsearch_id="bar")&lt;/FONT&gt;" which filters the events from the base search.&lt;/P&gt;</description>
    <pubDate>Thu, 14 Jan 2021 01:46:37 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2021-01-14T01:46:37Z</dc:date>
    <item>
      <title>Filter search by subsearch values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Filter-search-by-subsearch-values/m-p/535692#M151406</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;What's the best way to filter a search against a set of unique id's in a subsearch?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Currently, approaching it as such:&lt;BR /&gt;&lt;BR /&gt;&amp;lt;events to filter against subsearch ids&amp;gt;&lt;BR /&gt;| join left subsearch_id&amp;nbsp;&lt;BR /&gt;| [search subsearch]&lt;BR /&gt;&lt;BR /&gt;Though, it's returning a 1:1 set v. all primary search events that contain a matching id.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2021 18:09:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Filter-search-by-subsearch-values/m-p/535692#M151406</guid>
      <dc:creator>ahcarpenter</dc:creator>
      <dc:date>2021-01-13T18:09:55Z</dc:date>
    </item>
    <item>
      <title>Re: Filter search by subsearch values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Filter-search-by-subsearch-values/m-p/535747#M151424</link>
      <description>&lt;P&gt;There's no much to work with in the question, but perhaps this gives you an idea.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;events to filter against subsearch ids&amp;gt; [search subsearch | return 1000 subsearch_id]&lt;/LI-CODE&gt;&lt;P&gt;The subsearch with &lt;FONT face="courier new,courier"&gt;return&lt;/FONT&gt; command returns a string of the type "&lt;FONT face="courier new,courier"&gt;(subsearch_id="foo" OR subsearch_id="bar")&lt;/FONT&gt;" which filters the events from the base search.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2021 01:46:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Filter-search-by-subsearch-values/m-p/535747#M151424</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-01-14T01:46:37Z</dc:date>
    </item>
  </channel>
</rss>

