index = aries sourcetype = onezone | fields aaa baa | stats values(aaa) as aaa | table aaa append [ search index = leo sourcetype =twofone | fields ccc | stats ccc ] | stats value(aaa) as sd , values(ccc) as cc
Now the optimizedQuery option of Splunk changed the "append" command in the search and replaced it with to "[ | " search (index = leo sourcetype=twofone etc..etc...."..... And my output doesn't change. Both version has same output.
My question is, in the world of subsearches is using "append" the same as using " [ | search (index = ....."
Is using ""[ | "" better in terms of performnce than using "append " ?