I am trying to pull a list of filtered IPs from one index and then use that list as a reference to see external traffic from another index. When I run the subsearch command alone it works perfectly and gives me the list I desired. But when I throw the outer search in the mix it gives me all the IP addresses associated with "that_place" and nothing is filtered.
Index= two sourcetype=two destip!=22.*
[ search index=one sourcetype=one
ostype="Thing1" OR ostype="Thing2" OR ostype="Thing3"
place="thatplace" rename ip AS src | dedup src | table src]
| table src,destip,destport,bytesin,bytesout
I'm pretty new to Splunk and I know there has to be a better way to complete a simple search across different indexes.