<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: foreach and subsearch values in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/foreach-and-subsearch-values/m-p/540901#M153086</link>
    <description>&lt;P&gt;The &lt;FONT face="courier new,courier"&gt;map&lt;/FONT&gt; command can be made to work, but it's overkill for this situation.&amp;nbsp; Just extract the index name from the search field using &lt;FONT face="courier new,courier"&gt;rex&lt;/FONT&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;... | rex field=search "=(?&amp;lt;indexName&amp;gt;.*)" | ...&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 23 Feb 2021 13:40:24 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2021-02-23T13:40:24Z</dc:date>
    <item>
      <title>foreach and subsearch values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/foreach-and-subsearch-values/m-p/540880#M153082</link>
      <description>&lt;P&gt;I am using a table of results&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt; a |   b |  c |   search           | d |    e  
===============================================
xx    yy   zzz   index=firstindex    bb    ppp 
yyy  qqq  eeee   index=secondindex   rr    sss
ttt  zxc  asd    index=thirdindex    uy    mmm&lt;/PRE&gt;
&lt;P&gt;&lt;BR /&gt;based on each result,&amp;nbsp; I would like to perform a&amp;nbsp; foreach command to loop through each row of results based on the "search" field and perform a subsearch based on the VALUES in the "search" field,&amp;nbsp; from a coding's perspective it would be something like&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;for each row: 

if field= search: 
      #use value in search
      [search value | return index to main search]

it should evaluate to something like this for each row 

if field=search:
      [search index=index1 | return index]&lt;/PRE&gt;
&lt;P&gt;My desired output is:&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;index  
==============  
firstindex
secondindex
thirdindex&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Is this possible? I have tried using&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;foreach * [eval if &amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;=="search"[search &amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;] ","[search &amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;]]&lt;BR /&gt;&lt;BR /&gt;but this does not seem to work.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;I am aware of the map command, however as my field results have the word index= before the actual index name, I am unable to do a&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;search
========================
index=firstindex   
index=secondindex
index=thirdindex&lt;/PRE&gt;
&lt;P&gt;&lt;BR /&gt;|map search="search index=$search$"&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;as I believe ^ would&amp;nbsp; resolve to map search="search index=index=firstindex "&lt;BR /&gt;&lt;BR /&gt;This would be an error. Is there anyway I can do something like&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;PRE&gt;|map search="search $search$| stats values(index)"

and have it return something like 

index
==========
firstindex
secondindex
thirdindex&lt;/PRE&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;Tried looking around in splunk community forums but they seem to point at map instead of foreach, I am really lost in how I can get around this issue and achieving my desired output, it would be great if someone with more splunk experience can assist me&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Feb 2021 17:49:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/foreach-and-subsearch-values/m-p/540880#M153082</guid>
      <dc:creator>splunk_new1</dc:creator>
      <dc:date>2021-02-22T17:49:36Z</dc:date>
    </item>
    <item>
      <title>Re: foreach and subsearch values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/foreach-and-subsearch-values/m-p/540901#M153086</link>
      <description>&lt;P&gt;The &lt;FONT face="courier new,courier"&gt;map&lt;/FONT&gt; command can be made to work, but it's overkill for this situation.&amp;nbsp; Just extract the index name from the search field using &lt;FONT face="courier new,courier"&gt;rex&lt;/FONT&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;... | rex field=search "=(?&amp;lt;indexName&amp;gt;.*)" | ...&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Feb 2021 13:40:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/foreach-and-subsearch-values/m-p/540901#M153086</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-02-23T13:40:24Z</dc:date>
    </item>
    <item>
      <title>Re: foreach and subsearch values</title>
      <link>https://community.splunk.com/t5/Splunk-Search/foreach-and-subsearch-values/m-p/540948#M153109</link>
      <description>&lt;P&gt;Ah, appreciate this, I have tried it but it does not seem to work..&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;As the search field values may contain more than just one index, it does not seem to be possible, it would be ideal if the entire search field values can be just passed into the search itself as this is the search query.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;search&lt;/P&gt;&lt;P&gt;=============&lt;BR /&gt;index=index1&lt;/P&gt;&lt;P&gt;index=index2&lt;/P&gt;&lt;P&gt;index=index3&lt;BR /&gt;index=(index1 OR index2 OR index3) sourcetype=blahblah&lt;BR /&gt;index=`test`&lt;/P&gt;</description>
      <pubDate>Tue, 23 Feb 2021 02:45:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/foreach-and-subsearch-values/m-p/540948#M153109</guid>
      <dc:creator>splunk_new1</dc:creator>
      <dc:date>2021-02-23T02:45:22Z</dc:date>
    </item>
  </channel>
</rss>

