Splunk Search

How to check if a value exists in a list of values?

sdhiaeddine
Explorer

Hi,

I'm filtering a search to get a result for a specific values by checking it manually this way:

.... | stats sum(val) as vals by value | where value="v1" OR value="v2" OR value="v3"

I'm wondering if it is possible to do the same by checking if the value exists in a list coming from another index:
(something like this)

.... | append [search index=another_index
| stats values(remote_value) as values_list]
| stats sum(val) as vals by value | where (value in values_list)

Labels (3)
Tags (2)
0 Karma

DanielPriceUK
Path Finder
0 Karma

DanielPriceUK
Path Finder

use subsearches and the format command for the rest if you want to populate the comma seperated list with values from a search

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud’s AI Assistant in Action Series: Analyzing and ...

This is the second post in our Splunk Observability Cloud’s AI Assistant in Action series, in which we look at ...

Elevate Your Organization with Splunk’s Next Platform Evolution

 Thursday, July 10, 2025  |  11AM PDT / 2PM EDT Whether you're managing complex deployments or looking to ...

Splunk Answers Content Calendar, June Edition

Get ready for this week’s post dedicated to Splunk Dashboards! We're celebrating the power of community by ...