<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why does the subsearch example in the Splunk Search Tutorial seems to repeat itself? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-does-the-subsearch-example-in-the-Splunk-Search-Tutorial/m-p/218560#M64236</link>
    <description>&lt;P&gt;Thank you Somesoni2, really clear explanation ! &lt;BR /&gt;
I will add this to the Search Tutorial and to the Search Reference so that others are not confused.&lt;/P&gt;</description>
    <pubDate>Mon, 03 Oct 2016 15:44:09 GMT</pubDate>
    <dc:creator>lstewart_splunk</dc:creator>
    <dc:date>2016-10-03T15:44:09Z</dc:date>
    <item>
      <title>Why does the subsearch example in the Splunk Search Tutorial seems to repeat itself?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-does-the-subsearch-example-in-the-Splunk-Search-Tutorial/m-p/218558#M64234</link>
      <description>&lt;P&gt;I'm stepping through the main Splunk Search Tutorial.  I'm at the "subsearch" section: &lt;A href="https://docs.splunk.com/Documentation/Splunk/6.4.3/SearchTutorial/Useasubsearch"&gt;https://docs.splunk.com/Documentation/Splunk/6.4.3/SearchTutorial/Useasubsearch&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;The cited example search is the following:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;sourcetype=access_* status=200 action=purchase [search sourcetype=access_* status=200 action=purchase | top limit=1 clientip | table clientip] | stats count, dc(productId), values(productId) by clientip
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;What seems curious to me is that the subsearch begins with the entire content of the "outer search", being &lt;CODE&gt;sourcetype=access_* status=200 action=purchase&lt;/CODE&gt;.  It seems odd to me that the subsearch needs to repeat the entire outer search, and then qualifying it.  Is it perhaps that this is just a nonsensical subsearch use case?&lt;/P&gt;</description>
      <pubDate>Fri, 30 Sep 2016 20:21:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-does-the-subsearch-example-in-the-Splunk-Search-Tutorial/m-p/218558#M64234</guid>
      <dc:creator>davidmichaelkar</dc:creator>
      <dc:date>2016-09-30T20:21:10Z</dc:date>
    </item>
    <item>
      <title>Re: Why does the subsearch example in the Splunk Search Tutorial seems to repeat itself?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-does-the-subsearch-example-in-the-Splunk-Search-Tutorial/m-p/218559#M64235</link>
      <description>&lt;P&gt;The answer lies in the requirement. Below is the requirement of search, for that example&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;You want to find the single most frequent shopper on the Buttercup Games online store and what that shopper has purchased. Use the top command to return the most frequent shopper.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Now, remember data for both frequent shopper and purchases is coming from same data.&lt;/P&gt;

&lt;P&gt;So, Step 1 was to find single most frequent shopper, If you check the subsearch, that's what it gets (gets the clientip of the single most frequent buyer).&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;sourcetype=access_* status=200 action=purchase | top limit=1 clientip | table clientip
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Now, for this clientip, we need to get all the purchases, which we'll find in the same data using which we calculated most frequent buyer. So the outer search uses same data (successful purchases) and filter it for just that single clietip as returned by subsearch.&lt;/P&gt;

&lt;P&gt;This is how it'll look if you don't use this simplistic method&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;sourcetype=access_* status=200 action=purchase  | stats count, dc(productId), values(productId) by clientip | sort 0 -count | head 1
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Here, you're getting list of purchases of all buyers/clientip and then in the end, getting the most frequent ( by sorting and taking top 1 record). The former method, applies the filter in the base search itself, even though it has to run a subsearch, drastically (based on data of course) reducing the number of records that search has to process.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Sep 2016 21:34:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-does-the-subsearch-example-in-the-Splunk-Search-Tutorial/m-p/218559#M64235</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2016-09-30T21:34:54Z</dc:date>
    </item>
    <item>
      <title>Re: Why does the subsearch example in the Splunk Search Tutorial seems to repeat itself?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-does-the-subsearch-example-in-the-Splunk-Search-Tutorial/m-p/218560#M64236</link>
      <description>&lt;P&gt;Thank you Somesoni2, really clear explanation ! &lt;BR /&gt;
I will add this to the Search Tutorial and to the Search Reference so that others are not confused.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Oct 2016 15:44:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-does-the-subsearch-example-in-the-Splunk-Search-Tutorial/m-p/218560#M64236</guid>
      <dc:creator>lstewart_splunk</dc:creator>
      <dc:date>2016-10-03T15:44:09Z</dc:date>
    </item>
  </channel>
</rss>

