Splunk Cloud Platform

Subsearch not working on Splunk Cloud

tomazenix
Loves-to-Learn Lots

Hi,

This seems super dumb, but I've been fiddling with this for an embarrassingly long time now. It's been a couple of years since I've written any sub-searches.

I'm attempting to project data from the subqueries into a summary table (all from the same root search results)

This is running on splunk cloud under a trial license.

See dumbed down queries belong.

Happily returns a result:

 

 

index=xxx
| search index=xxx admintom | stats count as x | table x 
| table  x

 

 


Format returns nothing (`format` shows `NOT()`)

 

 

index=xxx
[ search index=xxx admintom | stats count as x | table x ]
| table  x

 

 

 

sub.pngno_sub.png

Labels (1)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

Your search which has the subsearch is doing

a) count the occurrence of 'adminton' in index=xxx

b) pass the result of that query as a search constraint to the outer search

i.e. if we assume the subsearch has run, your outer search is doing

index=xxx x=48
| table x

 don't really understand what you're trying to do though, but I suspect that's not it?

0 Karma
Get Updates on the Splunk Community!

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

A Guide To Cloud Migration Success

As enterprises’ rapid expansion to the cloud continues, IT leaders are continuously looking for ways to focus ...

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...