Splunk Search

find other results using search results from first query

New Member

its been a while since I've worked with splunk


I have an error detail that I can search in splunk:

index=* errorMessage

and it returns:

dateTime - sessionId - errorMessage

if I search the sessionId I get:

index=* sessionId

dateTime - sessionId - customerDetail



How can I find the customerDetail using one query by searching for the errorMessage?





Labels (3)
0 Karma


A subsearch should handle that.

index=* sessionId [index=* errorMessage | fields sessionId | format]

I hope you are using real index names in your queries as index=* is very inefficient. 

If this reply helps you, an upvote would be appreciated.
.conf21 Now Fully Virtual!
Register for FREE Today!

We've made .conf21 totally virtual and totally FREE! Our completely online experience will run from 10/19 through 10/20 with some additional events, too!