Splunk Search

How do you pass a field into a subsearch?


There are a few other similar questions on Splunk answers, but each answer has been tailored to each asker's use case. I'm obviously also looking to get it answered for my use case, but I'd prefer answers that are also more broadly applicable to the community.

I have an exchange-based alert set up that looks for suspicious emails every three minutes and sends out an alert if one is found with the fields "sender message_subject recipient". I want to add a "seen_count" field that has a count of how many times we've seen that sender over all-time. Basically, I want to be able to do:

... <search> ... | table sender message_subject recipient | eval seen_count=[search index=msexchange event_id=DELIVER sender=$sender$ earliest=-999d latest=now | stats count | return $count]

Since you can't pass values into a subsearch, how do I do this elegantly? I could count ALL my exchange senders and then left join with that, or create daily reports that update an aggregate sender_count.csv file every day, but neither of those solutions are elegant.

0 Karma


Here's one answer... looking for a better one

<lengthy base search> | table sender message_subject recipient | join type=left sender [<lengthy base search copied and pasted> | table sender message_subject recipient | map search="search index=msexchange event_id=DELIVER sender=$sender$ earliest=-999d latest=now | eventstats count as seen_count | dedup sender | table sender seen_count"]
0 Karma
Get Updates on the Splunk Community!

Announcing the 1st Round Champion’s Tribute Winners of the Great Resilience Quest

We are happy to announce the 20 lucky questers who are selected to be the first round of Champion's Tribute ...

We’ve Got Education Validation!

Are you feeling it? All the career-boosting benefits of up-skilling with Splunk? It’s not just a feeling, it's ...

What’s New in Splunk Cloud Platform 9.1.2308?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2308! Analysts can ...