<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Search on existing search results? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Search-on-existing-search-results/m-p/549167#M155793</link>
    <description>&lt;P&gt;Use &lt;FONT face="courier new,courier"&gt;loadjob&lt;/FONT&gt;.&amp;nbsp; Once the first search completes, use the Job Inspector to get the SID.&amp;nbsp; Then replace the original search with a &lt;FONT face="courier new,courier"&gt;loadjob&lt;/FONT&gt; command and add the new commands.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| loadjob 1619199687.119898 | search host=bar&lt;/LI-CODE&gt;&lt;P&gt;Note: the ability to do this without the &lt;FONT face="courier new,courier"&gt;loadjob&lt;/FONT&gt; kludge is an old ask.&amp;nbsp; Go to&amp;nbsp;&lt;A href="https://ideas.splunk.com" target="_blank"&gt;https://ideas.splunk.com&lt;/A&gt;&amp;nbsp;to add your voice.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 23 Apr 2021 17:45:26 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2021-04-23T17:45:26Z</dc:date>
    <item>
      <title>Search on existing search results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-on-existing-search-results/m-p/549162#M155791</link>
      <description>&lt;P&gt;Preemptive note, I am not looking for instructions on how to run a subsearch.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have results from a completed search that goes back 90 days which took an extremely long time to run. Lets say the search was:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=foo&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now that I have those results, I need to filter them down, lets say I'd like to filter them down to:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=foo host=bar&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'd like to search within those results without Splunk having to query the entire indexer again to reduce the amount of time the second search takes. Basically, is there any way to have Splunk query the existing, cached results already on the search head rather than having to query the indexer twice?&lt;/P&gt;</description>
      <pubDate>Fri, 23 Apr 2021 17:25:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-on-existing-search-results/m-p/549162#M155791</guid>
      <dc:creator>Haybuck15</dc:creator>
      <dc:date>2021-04-23T17:25:08Z</dc:date>
    </item>
    <item>
      <title>Re: Search on existing search results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-on-existing-search-results/m-p/549167#M155793</link>
      <description>&lt;P&gt;Use &lt;FONT face="courier new,courier"&gt;loadjob&lt;/FONT&gt;.&amp;nbsp; Once the first search completes, use the Job Inspector to get the SID.&amp;nbsp; Then replace the original search with a &lt;FONT face="courier new,courier"&gt;loadjob&lt;/FONT&gt; command and add the new commands.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| loadjob 1619199687.119898 | search host=bar&lt;/LI-CODE&gt;&lt;P&gt;Note: the ability to do this without the &lt;FONT face="courier new,courier"&gt;loadjob&lt;/FONT&gt; kludge is an old ask.&amp;nbsp; Go to&amp;nbsp;&lt;A href="https://ideas.splunk.com" target="_blank"&gt;https://ideas.splunk.com&lt;/A&gt;&amp;nbsp;to add your voice.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Apr 2021 17:45:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-on-existing-search-results/m-p/549167#M155793</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-04-23T17:45:26Z</dc:date>
    </item>
  </channel>
</rss>

