Splunk Search

How to append a search and filter by values based off a parent search

New Member

I have a search for a dashboard and I'd like to filter it based on an IN search with results from parent search.
Is this possible?

| db "SELECT * FROM accounts" | append [| db SELECT * FROM accounts2 | search account_id NOT IN results_account_id]
0 Karma

Esteemed Legend

Forget all of your SPL. Show the events in both data sets and a mockup of the desired output.