Splunk Enterprise

Subsearch append question !!

zacksoft
Contributor

I have search query that looked like this,

index = aries sourcetype = onezone 
| fields aaa baa
| stats values(aaa) as aaa 
| table aaa
append
   [ search index = leo sourcetype =twofone
        | fields ccc
        | stats ccc ]
| stats value(aaa) as sd , values(ccc) as cc

Now the optimizedQuery option of Splunk changed the "append" command in the search and replaced it with  to "[  | " search (index = leo  sourcetype=twofone  etc..etc....".....
And my output doesn't change. Both version has same output.

My question is, in the world of subsearches is using "append" the same as  using " [ | search (index = ....."

Is using ""[ | "" better in terms of performnce than using "append "  ?

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

How Splunk processes a query internally does not necessarily imply you should or can write that query and differently.

If you ran this query you would get far different results (if any at all) than with the original.

index = aries sourcetype = onezone 
| fields aaa baa
| stats values(aaa) as aaa 
| table aaa
[ search index = leo sourcetype =twofone
    | fields ccc
    | stats ccc ]
| stats value(aaa) as sd , values(ccc) as cc
---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Build the Future of Agentic AI: Join the Splunk Agentic Ops Hackathon

AI is changing how teams investigate incidents, detect threats, automate workflows, and build intelligent ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...