The reason is to search some value, eval this as a value or combined multivalie and search eval field=1 as | search 1
Hi @borisk95,
You can run the following search for the same results if you're trying to filter on the DATA field :
|search sourcetype=syslog [search tratata | eval ip=somedata|rename ip AS DATA | return $DATA]
Cheers,
David
First run the subsearch by itself to verify you get the expected results.
search tratata | eval ip=somedata | return $ip
You may have better luck with
search tratata | eval ip=somedata | fields ip | format
Modify the search as needed to get the desired output. Once you have the output as you like it, put the query together.
sourcetype=syslog | eval DATA=[search tratata | eval ip=somedata | fields ip | format] | search DATA
Or perhaps
sourcetype=syslog [search tratata | eval ip=somedata | fields ip | format]
Please describe the problem you are trying to solve. There may be a better way to do it.
I'm trying to eval value from subsearch
ex searching specific data collecting them to multivalue field and pass to variable than search.
Do splunk have variables something like global variables