Splunk Search

query a field with result from another query

Cbr1sg
Path Finder

Hello all,
I have query1 looks like below:

<query1> | fields dialog1 | table dialog1

I want to have query2 to search for all events that field Dialog matches results from query1, something like below:

index=abc Dialog=dialog1

Problem is there could be more than 1 value of dialog1, how can I compare them one by one with Dialog?

I know the join command can work in this case, by first doing index=abc and then filtering out the result by joining the 2 queries together via Dialog field. However this is no good as there would be too much of data if I search by index=abc alone.

Anyone knows a better way to do this? Thanks

Tags (2)
0 Karma
1 Solution

renjith_nair
Legend

Does sub search help here?

http://docs.splunk.com/Documentation/Splunk/7.1.1/Search/Aboutsubsearches

---
What goes around comes around. If it helps, hit it with Karma 🙂

View solution in original post

0 Karma

renjith_nair
Legend

Does sub search help here?

http://docs.splunk.com/Documentation/Splunk/7.1.1/Search/Aboutsubsearches

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma

Cbr1sg
Path Finder

Exactly what I'm looking for. Thank you very much!

0 Karma

renjith_nair
Legend

Ok, please accept as answer so that the thread is closed

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...