Splunk Search

find other results using search results from first query

New Member

its been a while since I've worked with splunk


I have an error detail that I can search in splunk:

index=* errorMessage

and it returns:

dateTime - sessionId - errorMessage

if I search the sessionId I get:

index=* sessionId

dateTime - sessionId - customerDetail



How can I find the customerDetail using one query by searching for the errorMessage?





Labels (3)
0 Karma


A subsearch should handle that.

index=* sessionId [index=* errorMessage | fields sessionId | format]

I hope you are using real index names in your queries as index=* is very inefficient. 

If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

How I Instrumented a Rust Application Without Knowing Rust

As a technical writer, I often have to edit or create code snippets for Splunk's distributions of ...

Splunk Community Platform Survey

Hey Splunk Community, Starting today, the community platform may prompt you to participate in a survey. The ...

Observability Highlights | November 2022 Newsletter

 November 2022Observability CloudEnd Of Support Extension for SignalFx Smart AgentSplunk is extending the End ...