Splunk Search

order of sub searches changed when using saved search or the summary page

Communicator

in 4.1.6 On the UI, I can run a search with a sub search in the condition.

index="_internal" source="log" OR [ search index=_internal source="etrics" | head 2 |table source ] | table source

But when I save it and call it from the "saved search" menu. Or that I type it on the summary page, on the result page, all got wrong because the order changed.

the [ search ...] block is now at the beginning of the line

[ search index=_internal source="etrics" | head 2 |table source ] index="_internal" source="log" OR | table source

Tags (2)
1 Solution

Splunk Employee
Splunk Employee

This was brought to support's attention last week. It's an intentions issue and this behavior is already fixed on 4.2
Perhaps it will also be fixed in the next maintenance release, you could try creating a case with support so that your issue gets logged as well.

Cheers

View solution in original post

Splunk Employee
Splunk Employee

This was brought to support's attention last week. It's an intentions issue and this behavior is already fixed on 4.2
Perhaps it will also be fixed in the next maintenance release, you could try creating a case with support so that your issue gets logged as well.

Cheers

View solution in original post

Communicator

thanks Genti Sama.

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!