Splunk Search

Difference between base query, master query and independent query

Dheeru
Engager

Hi,

I am new to splunk and I am trying to create a dashboard with optimizing the independent queries and by using all the same base queries. Kindly let me know the difference between independent,master and base queries.

Labels (1)
0 Karma
1 Solution

bowesmana
SplunkTrust
SplunkTrust

This page tells you about the types of searches you can have in dashboards.

https://docs.splunk.com/Documentation/Splunk/8.1.3/Viz/Savedsearches

but basically a base search is something that you can use as a building block for other searches, e.g.

<search id="this_is_a_base_search>
  <query>
index=_internal
| stats count by user
  </query>
</search>

and then you can have other searches that build in that, e.g. you could have a single panel showing a count for two users that uses that base search, such as

<single>
  <search base="this_is_a_base_search">
    <query>
| where user="admin"
    </query>
  </search>
</single>

and

<single>
  <search base="this_is_a_base_search">
    <query>
| where user="Dheeru"
    </query>
  </search>
</single>

 they would use the results from the first search.

You can also have multiple levels of base search, so a search can be also a base search but use another base search, e.g. from the above search, it could be...

<single>
  <search id="i_am_a_new_base_search" base="this_is_a_base_search">
    <query>
| where user="Dheeru"
    </query>
  </search>
</single>

 

View solution in original post

0 Karma

bowesmana
SplunkTrust
SplunkTrust

This page tells you about the types of searches you can have in dashboards.

https://docs.splunk.com/Documentation/Splunk/8.1.3/Viz/Savedsearches

but basically a base search is something that you can use as a building block for other searches, e.g.

<search id="this_is_a_base_search>
  <query>
index=_internal
| stats count by user
  </query>
</search>

and then you can have other searches that build in that, e.g. you could have a single panel showing a count for two users that uses that base search, such as

<single>
  <search base="this_is_a_base_search">
    <query>
| where user="admin"
    </query>
  </search>
</single>

and

<single>
  <search base="this_is_a_base_search">
    <query>
| where user="Dheeru"
    </query>
  </search>
</single>

 they would use the results from the first search.

You can also have multiple levels of base search, so a search can be also a base search but use another base search, e.g. from the above search, it could be...

<single>
  <search id="i_am_a_new_base_search" base="this_is_a_base_search">
    <query>
| where user="Dheeru"
    </query>
  </search>
</single>

 

0 Karma
Get Updates on the Splunk Community!

Splunk Answers Content Calendar, June Edition

Get ready for this week’s post dedicated to Splunk Dashboards! We're celebrating the power of community by ...

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...