Splunk Cloud Platform

Subsearch not working on Splunk Cloud

tomazenix
Loves-to-Learn Lots

Hi,

This seems super dumb, but I've been fiddling with this for an embarrassingly long time now. It's been a couple of years since I've written any sub-searches.

I'm attempting to project data from the subqueries into a summary table (all from the same root search results)

This is running on splunk cloud under a trial license.

See dumbed down queries belong.

Happily returns a result:

 

 

index=xxx
| search index=xxx admintom | stats count as x | table x 
| table  x

 

 


Format returns nothing (`format` shows `NOT()`)

 

 

index=xxx
[ search index=xxx admintom | stats count as x | table x ]
| table  x

 

 

 

sub.pngno_sub.png

Labels (1)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

Your search which has the subsearch is doing

a) count the occurrence of 'adminton' in index=xxx

b) pass the result of that query as a search constraint to the outer search

i.e. if we assume the subsearch has run, your outer search is doing

index=xxx x=48
| table x

 don't really understand what you're trying to do though, but I suspect that's not it?

0 Karma
Get Updates on the Splunk Community!

Learn Splunk Insider Insights, Do More With Gen AI, & Find 20+ New Use Cases You Can ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Buttercup Games: Further Dashboarding Techniques (Part 7)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Stay Connected: Your Guide to April Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...