Splunk Search

How to use the results of subsearch?

smanojkumar
Contributor

My requirement is to utilize the results of the sub-search and use it with the results of the main search results, but the sourcetype/source is different for the main search and sub-search, Im not getting the excepted results when using format command or $field_name,


inputlookup host.csv - consists of list of hosts to be monitored

main search 

index=abc source=cpu sourcetype=cpu CPU=all
[| inputlookup host.csv ]
| eval host=mvindex(split(host,"."),0)
| stats avg(pctIdle) AS CPU_Idle by host
| eval CPU_Idle=round(CPU_Idle,0)
| eval warning=15, critical=10
| where CPU_Idle<=warning
| sort CPU_Idle

sub-search
[search index=abc source=top
| dedup USER
| return $USER]
Labels (1)
0 Karma

smanojkumar
Contributor

Thanks!, there is a field host , which is common in both

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

It is not clear how you want to use the users returned by the sub-search.

Do the events from index=abc source=cpu sourcetype=cpu contain a USER field?

0 Karma

smanojkumar
Contributor

No ,the events from index=abc source=cpu sourcetype=cpu does not contain a USER field, since the USER field is there when source=top, not in source=cpu

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

So, how are you going to correlate events from the first search with events from the subsearch?

0 Karma

smanojkumar
Contributor

Thanks!, there is a field host , which is common in both

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...