Splunk Search

Subsearch only returns 1 value

Explorer

The search below produces multiple values for c_ip

index=proxy*
| fields cip sop dip rhost dport csbytes csuri referer cagent
| lookup RedSkyIOCip-Proxy Indicator AS dip OUTPUT Source ReferenceAttribution
| search Source=RedSkyIOC
| table _time c
ip dip Source ReferenceAttribution csuri referer c_agent

When it is modified to become a subsearch as below, the subsearch only returns 1 value for c_ip. What is not working?

index=in_index
[ search index=proxy

| fields cip sop dip rhost dport csbytes csuri referer cagent
| lookup RedSkyIOCip-Proxy Indicator AS dip OUTPUT Source ReferenceAttribution
| search Source=RedSkyIOC
| dedup c
ip
| rename cip AS sip
| return sip ]
| table _time s
ip dip dport action | sort s_ip

Tags (1)
0 Karma

SplunkTrust
SplunkTrust

The return command defaults to returning a single value. Try replacing it with a field command.

---
If this reply helps you, an upvote would be appreciated.
0 Karma