Splunk Cloud Platform

Subsearch not working on Splunk Cloud

tomazenix
Loves-to-Learn Lots

Hi,

This seems super dumb, but I've been fiddling with this for an embarrassingly long time now. It's been a couple of years since I've written any sub-searches.

I'm attempting to project data from the subqueries into a summary table (all from the same root search results)

This is running on splunk cloud under a trial license.

See dumbed down queries belong.

Happily returns a result:

 

 

index=xxx
| search index=xxx admintom | stats count as x | table x 
| table  x

 

 


Format returns nothing (`format` shows `NOT()`)

 

 

index=xxx
[ search index=xxx admintom | stats count as x | table x ]
| table  x

 

 

 

sub.pngno_sub.png

Labels (1)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

Your search which has the subsearch is doing

a) count the occurrence of 'adminton' in index=xxx

b) pass the result of that query as a search constraint to the outer search

i.e. if we assume the subsearch has run, your outer search is doing

index=xxx x=48
| table x

 don't really understand what you're trying to do though, but I suspect that's not it?

0 Karma
Get Updates on the Splunk Community!

Video | Welcome Back to Smartness, Pedro

Remember Splunk Community member, Pedro Borges? If you tuned into Episode 2 of our Smartness interview series, ...

Detector Best Practices: Static Thresholds

Introduction In observability monitoring, static thresholds are used to monitor fixed, known values within ...

Expert Tips from Splunk Education, Observability in Action, Plus More New Articles on ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...