Splunk Search

Filter result with another search

rxalex
Engager

Hi Folks, I have been trying to pull some data associated with latest Run ID (associated with execution), I am having hard time writing query for it. Any help would be appreciated.

Base Data:

 

index="unified-tests" dataType="TestRail"

 

To this I would need to apply a filter for runId = result of below query

 

index="unified-tests" dataType="TestRail" | stats last(runId) as latestRunID by brand, platform | stats last(latestRunID) by latestRunID | table latestRunID

 

These are some failed attempts:

 

index="unified-tests" dataType="TestRail" runId=*[search index="unified-tests" dataType="TestRail" | stats last(runId) as latestRunID by brand, platform | stats last(latestRunID) by latestRunID | table latestRunID]
index="unified-tests" dataType="TestRail" | join left=L right=R where L.runID = R.latestRunID [search index="unified-tests" dataType="TestRail" | stats last(runId) as latestRunID by brand, platform | stats last(latestRunID) by latestRunID | table latestRunID]

 

Labels (3)
Tags (3)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

Try something like this

index="unified-tests" dataType="TestRail" [search index="unified-tests" dataType="TestRail" | stats last(runId) as runId by brand, platform | fields runId]

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust

Try something like this

index="unified-tests" dataType="TestRail" [search index="unified-tests" dataType="TestRail" | stats last(runId) as runId by brand, platform | fields runId]

rxalex
Engager

Thanks a lot @ITWhisperer suggested solution worked

0 Karma
*NEW* Splunk Love Promo!
Snag a $25 Visa Gift Card for Giving Your Review!

It's another Splunk Love Special! For a limited time, you can review one of our select Splunk products through Gartner Peer Insights and receive a $25 Visa gift card!

Review:





Or Learn More in Our Blog >>