<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: injecting all rex field events from 1st search to 2nd search in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-inject-all-rex-field-events-from-1st-search-to-2nd/m-p/642878#M222657</link>
    <description>&lt;P&gt;Please can you provide more details on what you have so far as your description is a little vague and confusing?&lt;/P&gt;</description>
    <pubDate>Wed, 10 May 2023 15:46:48 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2023-05-10T15:46:48Z</dc:date>
    <item>
      <title>How can I inject all rex field events from 1st search to 2nd search?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-inject-all-rex-field-events-from-1st-search-to-2nd/m-p/642868#M222653</link>
      <description>&lt;P&gt;I am planning to build a dashboard where all the extracted traceId # are collected and injected to another search criteria where only the extracted traceId # from 1st search is passed to 2nd search and have a results, total count for the 1st search and total count for second search only with those regex traceId.&lt;/P&gt;
&lt;P&gt;I used the drop down and used regex but when passing the token, I.m selecting all the traceId where it passes as * in second search which is searching all not from the 1st search.&lt;/P&gt;
&lt;P&gt;is there a way to inject the 1st searched traceId to 2nd search ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2023 02:07:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-inject-all-rex-field-events-from-1st-search-to-2nd/m-p/642868#M222653</guid>
      <dc:creator>mikeyty07</dc:creator>
      <dc:date>2023-05-11T02:07:41Z</dc:date>
    </item>
    <item>
      <title>Re: injecting all rex field events from 1st search to 2nd search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-inject-all-rex-field-events-from-1st-search-to-2nd/m-p/642878#M222657</link>
      <description>&lt;P&gt;Please can you provide more details on what you have so far as your description is a little vague and confusing?&lt;/P&gt;</description>
      <pubDate>Wed, 10 May 2023 15:46:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-inject-all-rex-field-events-from-1st-search-to-2nd/m-p/642878#M222657</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-05-10T15:46:48Z</dc:date>
    </item>
    <item>
      <title>Re: injecting all rex field events from 1st search to 2nd search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-inject-all-rex-field-events-from-1st-search-to-2nd/m-p/643074#M222755</link>
      <description>&lt;P&gt;i want to trace logs for specific api that runs in sequence for specific transsaction.&lt;BR /&gt;like&amp;nbsp; api/search/brand--&amp;gt; api/buy/gucci --&amp;gt; api/gucci/custom --&amp;gt;api/purchased. and these logs have one field in common TrackingID. Is there a way to get all these logs events in table for total count of the api searched for api/search/clothes and the TrackingID from the first api to the second&amp;nbsp; api/buy/gucci total count and so on.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;2023-05-11T15:06:14 TrackingID =abcdgucci123 duration=600 uri="/api/search/brand" source=xyz&lt;BR /&gt;&lt;BR /&gt;2023-05-11T15:06:15 TrackingID =abcdgucci123 duration=500 uri="/api/buy/gucci" source=brb&lt;/P&gt;&lt;P&gt;2023-05-11T15:06:16 TrackingID =abcdgucci123 duration=500 uri="/api/gucci/custom" source=idk&lt;/P&gt;&lt;P&gt;2023-05-11T15:06:17 TrackingID =abcdgucci123 duration=500 uri="/api/purchased" source=abc&lt;BR /&gt;&lt;BR /&gt;this is just an example of logs there would be hunderds of these logs. Is there a way to get count of all api in table for the count of api called and so on through the&amp;nbsp;TrackingID to the next api being called?&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2023 15:39:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-inject-all-rex-field-events-from-1st-search-to-2nd/m-p/643074#M222755</guid>
      <dc:creator>mikeyty07</dc:creator>
      <dc:date>2023-05-11T15:39:13Z</dc:date>
    </item>
    <item>
      <title>Re: injecting all rex field events from 1st search to 2nd search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-inject-all-rex-field-events-from-1st-search-to-2nd/m-p/643076#M222756</link>
      <description>&lt;P&gt;Do you mean&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| stats count by TrackingID uri&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 11 May 2023 15:51:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-inject-all-rex-field-events-from-1st-search-to-2nd/m-p/643076#M222756</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-05-11T15:51:38Z</dc:date>
    </item>
  </channel>
</rss>

