Splunk Search

How to set field in subsearch?

sbimizry
Engager

Hi, how to a must write search then set fields from general search to subsearch?
Example:
index=name host=thishost | eval ip=iphost+"\\" | eval counts=[ search index=name2 | where iphost=ip | return $iphost ]
Field ip created in general search, how to use this field to subsearch?
How I must make it?
Thanks

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Since subsearches execute before the main search, nothing created by the main search is available in the subsearch.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Since subsearches execute before the main search, nothing created by the main search is available in the subsearch.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...