Splunk Search

How to use the results of subsearch?

smanojkumar
Communicator

My requirement is to utilize the results of the sub-search and use it with the results of the main search results, but the sourcetype/source is different for the main search and sub-search, Im not getting the excepted results when using format command or $field_name,


inputlookup host.csv - consists of list of hosts to be monitored

main search 

index=abc source=cpu sourcetype=cpu CPU=all
[| inputlookup host.csv ]
| eval host=mvindex(split(host,"."),0)
| stats avg(pctIdle) AS CPU_Idle by host
| eval CPU_Idle=round(CPU_Idle,0)
| eval warning=15, critical=10
| where CPU_Idle<=warning
| sort CPU_Idle

sub-search
[search index=abc source=top
| dedup USER
| return $USER]
Labels (1)
0 Karma

smanojkumar
Communicator

Thanks!, there is a field host , which is common in both

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

It is not clear how you want to use the users returned by the sub-search.

Do the events from index=abc source=cpu sourcetype=cpu contain a USER field?

0 Karma

smanojkumar
Communicator

No ,the events from index=abc source=cpu sourcetype=cpu does not contain a USER field, since the USER field is there when source=top, not in source=cpu

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

So, how are you going to correlate events from the first search with events from the subsearch?

0 Karma

smanojkumar
Communicator

Thanks!, there is a field host , which is common in both

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...