Splunk Search

Subsearch Not Filtering Results

New Member

I am trying to pull a list of filtered IPs from one index and then use that list as a reference to see external traffic from another index. When I run the subsearch command alone it works perfectly and gives me the list I desired. But when I throw the outer search in the mix it gives me all the IP addresses associated with "that_place" and nothing is filtered.

Index= two sourcetype=two destip!=22.*
[ search index=one sourcetype=one
os
type="Thing1" OR ostype="Thing2" OR ostype="Thing3"
NOT os
type!="Thing4"
NOT os
description="Thing5"
NOT os
description="Thing6"
NOT os
hostname="Thing7"
place="that
place" rename ip AS src | dedup src | table src]
| table src,destip,destport,bytesin,bytesout

I'm pretty new to Splunk and I know there has to be a better way to complete a simple search across different indexes.

0 Karma

New Member

Sorry that was a typo. should read:

place="that_place" | rename ip AS src

0 Karma

Explorer

place="that_place" rename ip AS src

In your rename command, there is no leading pipe or its typo ?

Anyways I think better to move dedup in outer search

0 Karma