Splunk Search
Highlighted

How to edit my subsearch to look up a predefined field comprised of rex in my main search?

Explorer

My subsearch contains this predefined field, and I'm trying to use it to search my main search that gets the field using rex, but I get no results.

I've tried a few different things:

host=blah... [search...| table my_field] | rex field=_raw "...<my_field>..."

host=blah... |rex field=_raw "...<my_field>..." | regex [search... | table my_field]

host=blah... | rex field=_raw "...<my_field>..." | regex my_field=[search...| table my_field]
0 Karma
Highlighted

Re: How to edit my subsearch to look up a predefined field comprised of rex in my main search?

Legend

Try this

host=blah... | rex field=_raw "...<my_field>..." | search [search... | table my_field ]

View solution in original post

Highlighted

Re: How to edit my subsearch to look up a predefined field comprised of rex in my main search?

Explorer

so simple. thanks!

0 Karma