Splunk Search

order of sub searches changed when using saved search or the summary page

mataharry
Communicator

in 4.1.6 On the UI, I can run a search with a sub search in the condition.

index="_internal" source="log" OR [ search index=_internal source="etrics" | head 2 |table source ] | table source

But when I save it and call it from the "saved search" menu. Or that I type it on the summary page, on the result page, all got wrong because the order changed.

the [ search ...] block is now at the beginning of the line

[ search index=_internal source="etrics" | head 2 |table source ] index="_internal" source="log" OR | table source

Tags (2)
1 Solution

Genti
Splunk Employee
Splunk Employee

This was brought to support's attention last week. It's an intentions issue and this behavior is already fixed on 4.2
Perhaps it will also be fixed in the next maintenance release, you could try creating a case with support so that your issue gets logged as well.

Cheers

View solution in original post

Genti
Splunk Employee
Splunk Employee

This was brought to support's attention last week. It's an intentions issue and this behavior is already fixed on 4.2
Perhaps it will also be fixed in the next maintenance release, you could try creating a case with support so that your issue gets logged as well.

Cheers

mataharry
Communicator

thanks Genti Sama.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...