Splunk Search

Using Results from a search and use them in a new search

akelly4
Path Finder

I'm trying to figure out if it's possible to take the results out of a search and define them and automatically use them in a subsearch. The results will change each time the search is ran.

As an example, in the log below I am pulling out "32573", "D2E8DB9A3F_4761818F", "54461818_23272_700_1", and "18909934C1_4761819B". I've defined all of those as fields and now I want to be able to run a separate search that looks for logs that contain that information.

Nov 26 13:12:41 10.255.220.2 Nov 26 18:12:41 sm03 postfix/smtp[32573]: D2E8DB9A3F_4761818F: to=, relay=127.0.0.1[127.0.0.1]:10025, delay=0.2, delays=0.01/0/0/0.19, dsn=2.0.0, status=sent (250 OK, sent 54461818_23272_700_1 1980934C1_4761819B)

Does anyone know if this is possible? If so can you just point me in the direction of what I could use to accomplish this?

Tags (1)
0 Karma

kendrickt
Path Finder

I'm pretty sure Workflows are what you need as they can:

"Launch secondary Splunk Enterprise searches that use one or more field values from selected events"

Take a look here:

Workflows

http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/CreateworkflowactionsinSplunkWeb?r=sear...

0 Karma

changux
Builder
0 Karma

kendrickt
Path Finder

Hi akelly,

Have you tried looking at Workflows?

You can forward data from a field into a new search or to an external site?

Workflow Actions

http://docs.splunk.com/Splexicon:Workflowaction

0 Karma
Get Updates on the Splunk Community!

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

New Release | Splunk Cloud Platform 10.1.2507

Hello Splunk Community!We are thrilled to announce the General Availability of Splunk Cloud Platform 10.1.2507 ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...