Splunk Search

How to check if a value exists in a list of values?

sdhiaeddine
Explorer

Hi,

I'm filtering a search to get a result for a specific values by checking it manually this way:

.... | stats sum(val) as vals by value | where value="v1" OR value="v2" OR value="v3"

I'm wondering if it is possible to do the same by checking if the value exists in a list coming from another index:
(something like this)

.... | append [search index=another_index
| stats values(remote_value) as values_list]
| stats sum(val) as vals by value | where (value in values_list)

Labels (3)
Tags (2)
0 Karma

DanielPriceUK
Path Finder
0 Karma

DanielPriceUK
Path Finder

use subsearches and the format command for the rest if you want to populate the comma seperated list with values from a search

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In September, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...