Not the best subject. I'm not sure how to explain it in the title. But I'd like to use the results of an custom search to limit my search results. psuedo-code:
customsearch returns a field named "customresults"
sourcetype of "xyz" has a field called "expected_results"
sourcetype="xyz" | custom_search | search expected_results=custom_results
However, the search command takes the "results" literally, instead of the field contents.
How is this achieved?
Use where instead of search -
sourcetype="xyz" | custom_search | where expected_results=custom_results