Splunk Cloud Platform

Subsearch not working on Splunk Cloud

tomazenix
Loves-to-Learn Lots

Hi,

This seems super dumb, but I've been fiddling with this for an embarrassingly long time now. It's been a couple of years since I've written any sub-searches.

I'm attempting to project data from the subqueries into a summary table (all from the same root search results)

This is running on splunk cloud under a trial license.

See dumbed down queries belong.

Happily returns a result:

 

 

index=xxx
| search index=xxx admintom | stats count as x | table x 
| table  x

 

 


Format returns nothing (`format` shows `NOT()`)

 

 

index=xxx
[ search index=xxx admintom | stats count as x | table x ]
| table  x

 

 

 

sub.pngno_sub.png

Labels (1)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

Your search which has the subsearch is doing

a) count the occurrence of 'adminton' in index=xxx

b) pass the result of that query as a search constraint to the outer search

i.e. if we assume the subsearch has run, your outer search is doing

index=xxx x=48
| table x

 don't really understand what you're trying to do though, but I suspect that's not it?

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...