<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Subquery Event count in not work i need to count sub query in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Subquery-Event-count-in-not-work-i-need-to-count-sub-query/m-p/181262#M52260</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;You can try using eventstats instead of stats. Ideally, the join command expects one or many common fields on both sides of the command. i.e. first query should have "audit" field and the subsearch should also have "audit" field.&lt;/P&gt;

&lt;P&gt;Thanks!!&lt;/P&gt;</description>
    <pubDate>Wed, 06 May 2015 09:50:56 GMT</pubDate>
    <dc:creator>vganjare</dc:creator>
    <dc:date>2015-05-06T09:50:56Z</dc:date>
    <item>
      <title>Subquery Event count in not work i need to count sub query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Subquery-Event-count-in-not-work-i-need-to-count-sub-query/m-p/181261#M52259</link>
      <description>&lt;P&gt;i create query in which i search unique no of values of one field and that unique value join to other query they work properly&lt;/P&gt;

&lt;P&gt;index="uk" sourcetype="uk18" serviceType=2 | eval ll=substr(message,0,18)  | where ll="getLogMsg returned"  |  rex field=message "^71^+(?&amp;lt;myAp&amp;gt;[^^]+)^" | eval result=if(myAp = 00,"sucess","fail") | join audit [search index="uk" sourcetype="uk18" serviceType=1 | dedup audit|fields + audit ] | stats count(audit) by result &lt;/P&gt;

&lt;P&gt;But when i use [stats count] in subquery they not work i want to count total no of result in subquery. i want to subtract sub query count with total result&lt;/P&gt;

&lt;P&gt;My query which not work is :&lt;BR /&gt;
index="uk" sourcetype="uk18" serviceType=2 | eval ll=substr(message,0,18)  | where ll="getLogMsg returned"  |  rex field=message "^71^+(?&amp;lt;myAp&amp;gt;[^^]+)^" | eval result=if(myAp = 00,"sucess","fail") | join audit [search index="uk" sourcetype="uk18" serviceType=1 | dedup audit|fields + audit | stats count as totall ] | stats count(audit) by result &lt;/P&gt;

&lt;P&gt;if you see i add [stats count as totall] in sub query&lt;/P&gt;</description>
      <pubDate>Wed, 06 May 2015 09:28:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Subquery-Event-count-in-not-work-i-need-to-count-sub-query/m-p/181261#M52259</guid>
      <dc:creator>nitesh218ss</dc:creator>
      <dc:date>2015-05-06T09:28:32Z</dc:date>
    </item>
    <item>
      <title>Re: Subquery Event count in not work i need to count sub query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Subquery-Event-count-in-not-work-i-need-to-count-sub-query/m-p/181262#M52260</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;You can try using eventstats instead of stats. Ideally, the join command expects one or many common fields on both sides of the command. i.e. first query should have "audit" field and the subsearch should also have "audit" field.&lt;/P&gt;

&lt;P&gt;Thanks!!&lt;/P&gt;</description>
      <pubDate>Wed, 06 May 2015 09:50:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Subquery-Event-count-in-not-work-i-need-to-count-sub-query/m-p/181262#M52260</guid>
      <dc:creator>vganjare</dc:creator>
      <dc:date>2015-05-06T09:50:56Z</dc:date>
    </item>
    <item>
      <title>Re: Subquery Event count in not work i need to count sub query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Subquery-Event-count-in-not-work-i-need-to-count-sub-query/m-p/181263#M52261</link>
      <description>&lt;P&gt;i use this way they run but in result how i get in result they show field result and count(audit) only not show sub query count&lt;BR /&gt;
my query is:&lt;BR /&gt;
| eval ll=substr(message,0,18)  | where ll="getLogMsg returned"  |  rex field=message "^71^+(?&amp;lt;myAp&amp;gt;[^^]+)^" | eval result=if(myAp = 00,"sucess","fail") | join audit [search index="uk" sourcetype="uk18" serviceType=1 | dedup audit|fields + audit | eventstats count as kk ] |stats count(audit) by result&lt;/P&gt;</description>
      <pubDate>Wed, 06 May 2015 11:14:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Subquery-Event-count-in-not-work-i-need-to-count-sub-query/m-p/181263#M52261</guid>
      <dc:creator>nitesh218ss</dc:creator>
      <dc:date>2015-05-06T11:14:41Z</dc:date>
    </item>
  </channel>
</rss>

