Splunk Search

query a field with result from another query

Cbr1sg
Path Finder

Hello all,
I have query1 looks like below:

<query1> | fields dialog1 | table dialog1

I want to have query2 to search for all events that field Dialog matches results from query1, something like below:

index=abc Dialog=dialog1

Problem is there could be more than 1 value of dialog1, how can I compare them one by one with Dialog?

I know the join command can work in this case, by first doing index=abc and then filtering out the result by joining the 2 queries together via Dialog field. However this is no good as there would be too much of data if I search by index=abc alone.

Anyone knows a better way to do this? Thanks

Tags (2)
0 Karma
1 Solution

renjith_nair
Legend

Does sub search help here?

http://docs.splunk.com/Documentation/Splunk/7.1.1/Search/Aboutsubsearches

---
What goes around comes around. If it helps, hit it with Karma 🙂

View solution in original post

0 Karma

renjith_nair
Legend

Does sub search help here?

http://docs.splunk.com/Documentation/Splunk/7.1.1/Search/Aboutsubsearches

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma

Cbr1sg
Path Finder

Exactly what I'm looking for. Thank you very much!

0 Karma

renjith_nair
Legend

Ok, please accept as answer so that the thread is closed

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma
Get Updates on the Splunk Community!

Index This | What goes away as soon as you talk about it?

May 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...

What's New in Splunk Observability Cloud and Splunk AppDynamics - May 2025

This month, we’re delivering several new innovations in Splunk Observability Cloud and Splunk AppDynamics ...

Getting Started with Splunk Artificial Intelligence, Insights for Nonprofits, and ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...