Splunk Search

Compare Search count of main query and subquery

javeeth
Loves-to-Learn

I have 2 search queries one is main and the other one is a subquery and i need to find the count difference between both the searches 

Labels (1)
0 Karma

javeeth
Loves-to-Learn

The subquery is not returning value not sure why.

Query 1 : eventtype=* | search status=200 | stats count as successCount

Query2 : eventtype=* | search status=500 | stats count as failedCount

I need to find both the count and calculate difference between them and display it

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Do you mean something like this?

base search
| stats count
| eval diff = count - [ subsearch | stats count | return $count ]
---
If this reply helps you, Karma would be appreciated.
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...

Introduction to Splunk AI

How are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. Lucky for ...