You can run the following search for the same results if you're trying to filter on the DATA field :
|search sourcetype=syslog [search tratata | eval ip=somedata|rename ip AS DATA | return $DATA]
First run the subsearch by itself to verify you get the expected results.
search tratata | eval ip=somedata | return $ip
You may have better luck with
search tratata | eval ip=somedata | fields ip | format
Modify the search as needed to get the desired output. Once you have the output as you like it, put the query together.
sourcetype=syslog | eval DATA=[search tratata | eval ip=somedata | fields ip | format] | search DATA
sourcetype=syslog [search tratata | eval ip=somedata | fields ip | format]
I'm trying to eval value from subsearch
ex searching specific data collecting them to multivalue field and pass to variable than search.
Do splunk have variables something like global variables