<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic New search using values from first search in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/New-search-using-values-from-first-search/m-p/247090#M73697</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;

&lt;P&gt;I can't seem to figure out how to use the values from a search and use those values to kick off another new search with those values.  I've tried append and using subsearches but don't seem to get the correct data back. I am not sure what the heck I am doing wrong. &lt;/P&gt;

&lt;P&gt;What I'd like to accomplish is search by a specific value which I input then use the results returned by the search to kick off a whole new search against all the data using those value.  &lt;/P&gt;

&lt;P&gt;For example if I search for buyer1 I get back one or more values I would like to then run a whole new search by passing each of those values to the new search and only get back those results.&lt;/P&gt;

&lt;P&gt;If I search for buyer1 I will back values &lt;STRONG&gt;5556677&lt;/STRONG&gt; and &lt;STRONG&gt;888999&lt;/STRONG&gt; for example&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;   sourcetype=buyer_data buyer="buyer1" | stats count by cust_id | fields - count
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I would like to then use those values as part of my next search to get the final IDs associated with that customer.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;  sourcetype=buyer_data (cust_id=5556677 OR cust_id=888999) | stats count by cust_id | dedup cust_id | fields - count
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This should return everything all record associated with this customer which is what I am looking to do.&lt;/P&gt;

&lt;P&gt;I tried running a subsearch and append&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;  sourcetype=buyer_data | stats count by id | append [|search sourcetype=buyer_data buyer="buyer1" | stats count by cust_id  | fields - count | eval id=buyer


   sourcetype=buyer_data * [ |search sourcetype=buyer_data buyer="buyer1" | stats count by cust_id | fields - count]


   sourcetype=buyer_data * stats count by id | append [|search sourcetype=buyer_data buyer="buyer1" | stats count by cust_id | eval id=cust_id
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Any help would be much appreciated. &lt;/P&gt;</description>
    <pubDate>Mon, 25 Jan 2016 17:05:07 GMT</pubDate>
    <dc:creator>splunker1981</dc:creator>
    <dc:date>2016-01-25T17:05:07Z</dc:date>
    <item>
      <title>New search using values from first search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/New-search-using-values-from-first-search/m-p/247090#M73697</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;

&lt;P&gt;I can't seem to figure out how to use the values from a search and use those values to kick off another new search with those values.  I've tried append and using subsearches but don't seem to get the correct data back. I am not sure what the heck I am doing wrong. &lt;/P&gt;

&lt;P&gt;What I'd like to accomplish is search by a specific value which I input then use the results returned by the search to kick off a whole new search against all the data using those value.  &lt;/P&gt;

&lt;P&gt;For example if I search for buyer1 I get back one or more values I would like to then run a whole new search by passing each of those values to the new search and only get back those results.&lt;/P&gt;

&lt;P&gt;If I search for buyer1 I will back values &lt;STRONG&gt;5556677&lt;/STRONG&gt; and &lt;STRONG&gt;888999&lt;/STRONG&gt; for example&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;   sourcetype=buyer_data buyer="buyer1" | stats count by cust_id | fields - count
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I would like to then use those values as part of my next search to get the final IDs associated with that customer.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;  sourcetype=buyer_data (cust_id=5556677 OR cust_id=888999) | stats count by cust_id | dedup cust_id | fields - count
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This should return everything all record associated with this customer which is what I am looking to do.&lt;/P&gt;

&lt;P&gt;I tried running a subsearch and append&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;  sourcetype=buyer_data | stats count by id | append [|search sourcetype=buyer_data buyer="buyer1" | stats count by cust_id  | fields - count | eval id=buyer


   sourcetype=buyer_data * [ |search sourcetype=buyer_data buyer="buyer1" | stats count by cust_id | fields - count]


   sourcetype=buyer_data * stats count by id | append [|search sourcetype=buyer_data buyer="buyer1" | stats count by cust_id | eval id=cust_id
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Any help would be much appreciated. &lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2016 17:05:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/New-search-using-values-from-first-search/m-p/247090#M73697</guid>
      <dc:creator>splunker1981</dc:creator>
      <dc:date>2016-01-25T17:05:07Z</dc:date>
    </item>
    <item>
      <title>Re: New search using values from first search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/New-search-using-values-from-first-search/m-p/247091#M73698</link>
      <description>&lt;P&gt;Hi splunker1981&lt;/P&gt;

&lt;P&gt;I believe the correct syntax in this example would be&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;sourcetype=buyer_data [sourcetype=buyer_data buyer="buyer1" | stats count by cust_id | fields - count]| stats count by cust_id | dedup cust_id | fields - count
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;If you are from an SQL background there is a good guide on how to think while crafting SPL queries: &lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/SQLtoSplunk"&gt;http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/SQLtoSplunk&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Let me know how you get along.&lt;/P&gt;

&lt;P&gt;j&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2016 17:15:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/New-search-using-values-from-first-search/m-p/247091#M73698</guid>
      <dc:creator>jbjerke_splunk</dc:creator>
      <dc:date>2016-01-25T17:15:20Z</dc:date>
    </item>
    <item>
      <title>Re: New search using values from first search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/New-search-using-values-from-first-search/m-p/247092#M73699</link>
      <description>&lt;P&gt;Thanks for the quick reply, jbjerke&lt;/P&gt;

&lt;P&gt;So I think that's the same result I was getting with all my previous attempts.  I ran your query and I get back the result from the first search, which returns back a value ID for buyer1.  In this case for example it returns back a value of 5556677&lt;/P&gt;

&lt;P&gt;What I need to do is then run a new search against all the dataset for the specific sourcetype and pass the value I just got with the query above.  Something like &lt;STRONG&gt;sourcetype=buyer_data 5556677&lt;/STRONG&gt; It should then be returning back three unique values, which is what I get if I were to take the value 5556677 manually and then do a new search like so. &lt;BR /&gt;
      index=cust_data sourcetype=buyer_data * 5556677 | dedup cust_id | table cust_id&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 08:33:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/New-search-using-values-from-first-search/m-p/247092#M73699</guid>
      <dc:creator>splunker1981</dc:creator>
      <dc:date>2020-09-29T08:33:02Z</dc:date>
    </item>
    <item>
      <title>Re: New search using values from first search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/New-search-using-values-from-first-search/m-p/247093#M73700</link>
      <description>&lt;P&gt;I figured out what the issue is but still not quite sure how to go about fixing it.  It appears that the result being passed is also specifying a field name.  When it goes to perform the second search it is specifying a fieldname along with the value, which is NOT what I am trying to do.  I just want to have it search on the value and not fieldname-&amp;gt;value combination. &lt;/P&gt;

&lt;P&gt;Instead of actually running the following query:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; sourcetype=buyer_data * 5556677
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;It is running this one which is why it's limiting my results.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; sourcetype=buyer_data * cust_id=5556677
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;How to I make the subsearch not pass a field name and only pass a value to the second search?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; [sourcetype=buyer_data buyer="buyer1" | stats count by cust_id | fields - count]
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 26 Jan 2016 11:47:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/New-search-using-values-from-first-search/m-p/247093#M73700</guid>
      <dc:creator>splunker1981</dc:creator>
      <dc:date>2016-01-26T11:47:05Z</dc:date>
    </item>
    <item>
      <title>Re: New search using values from first search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/New-search-using-values-from-first-search/m-p/247094#M73701</link>
      <description>&lt;P&gt;Figured out my own problem.  I needed to remove the stats count by cust_id in the first search and instead select the field using &lt;STRONG&gt;fields + cust_id&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;This worked for those trying to do the same:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;  sourcetype=buyer_data [sourcetype=buyer_data buyer="buyer1" | fields + cust_id | rename cust_id AS search ]| stats count by cust_id | dedup cust_id | fields - count
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 29 Sep 2020 08:35:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/New-search-using-values-from-first-search/m-p/247094#M73701</guid>
      <dc:creator>splunker1981</dc:creator>
      <dc:date>2020-09-29T08:35:25Z</dc:date>
    </item>
    <item>
      <title>Re: New search using values from first search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/New-search-using-values-from-first-search/m-p/247095#M73702</link>
      <description>&lt;P&gt;Hi splunker1981&lt;/P&gt;

&lt;P&gt;I believe you can achieve what you want by building a dynamic search filter with the commands mvcombine and nomv. The syntax would look something like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;   sourcetype=buyer_data [search sourcetype=buyer_data buyer="buyer1" | fields cust_id | mvcombine delim=" OR " cust_id | nomv cust_id| eval search="(".cust_id.")" | fields - cust_id]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The search above would essentially evaluate to this &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;   sourcetype=buyer_data (5556677 OR 888999)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Is this what you are looking for?&lt;/P&gt;

&lt;P&gt;j&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jan 2016 18:39:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/New-search-using-values-from-first-search/m-p/247095#M73702</guid>
      <dc:creator>jbjerke_splunk</dc:creator>
      <dc:date>2016-01-27T18:39:48Z</dc:date>
    </item>
    <item>
      <title>Re: New search using values from first search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/New-search-using-values-from-first-search/m-p/247096#M73703</link>
      <description>&lt;P&gt;Hi jbjerke - thanks for sticking with me here.  &lt;/P&gt;

&lt;P&gt;To answer your question; yes and no.  Let me try to explain a little better to see if that helps clear things up.  &lt;/P&gt;

&lt;P&gt;Your search partially gets me what I need.  What happens is that I am left with ALL the events (a good thing) which looks like what I pasted below as an example.  All of these events are currently parsed into their own fields with key/val pairs. &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;2015-01-01 ID=9999 SE=se_value01 PR=898989 I_ID=0001
2015-01-01 ID=9999 RE=re_value01 start=01
2015-01-01 ID=9999 SB=sb_value01 end=09
2015-01-01 ID=9999 AT=at_value01 pause=03
2015-01-01 ID=555 SE=se_value02 PR=55988 I_ID=000488
2015-01-01 ID=555 RE=re_value02 end=33
2015-01-01 ID=555 SB=sb_value02 UID=99990
2015-01-01 ID=555 AT=at_value02 UID=99990 pause=03
2015-01-01 I_ID=001 MAT=mat_value001 STAT=received SET=off EN=on
2015-01-01 I_ID=000488 MAT=mat_value000488 STAT=closed SET=on EN=off
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The problem I am running into is figuring out how to group the events, for reporting purposes by the two unique IDs?  For example - each set of events has an ID and mixed in within those IDs there's always one event that has and I_ID field.  What I would like to be able to say is - group events that have the same ID and I_ID &lt;STRONG&gt;(but keep in mind that I_ID only exists once per group of events)&lt;/STRONG&gt; and then be able to pull fields values based on that grouping to display in one row.  &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; 2015-01-01 9999  se_value01 sb_value01 at_value01 pause03 mat_value001 received
 2015-01-01 555   se_value02 sb_value02 at_value02 pause03 mat_value000488 closed
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 29 Sep 2020 08:39:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/New-search-using-values-from-first-search/m-p/247096#M73703</guid>
      <dc:creator>splunker1981</dc:creator>
      <dc:date>2020-09-29T08:39:19Z</dc:date>
    </item>
    <item>
      <title>Re: New search using values from first search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/New-search-using-values-from-first-search/m-p/247097#M73704</link>
      <description>&lt;P&gt;Hi splunker1981&lt;/P&gt;

&lt;P&gt;How about adding a stats grouping at the end of your search?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; THE INITIAL SEARCH | stats list(*) AS * by ID
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I think this should work with the sample data you posted. &lt;/P&gt;

&lt;P&gt;j&lt;/P&gt;</description>
      <pubDate>Mon, 08 Feb 2016 10:59:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/New-search-using-values-from-first-search/m-p/247097#M73704</guid>
      <dc:creator>jbjerke_splunk</dc:creator>
      <dc:date>2016-02-08T10:59:16Z</dc:date>
    </item>
  </channel>
</rss>

