Hello all,
I have query1 looks like below:
<query1> | fields dialog1 | table dialog1
I want to have query2 to search for all events that field Dialog matches results from query1, something like below:
index=abc Dialog=dialog1
Problem is there could be more than 1 value of dialog1, how can I compare them one by one with Dialog?
I know the join command can work in this case, by first doing index=abc and then filtering out the result by joining the 2 queries together via Dialog field. However this is no good as there would be too much of data if I search by index=abc alone.
Anyone knows a better way to do this? Thanks
Does sub search help here?
http://docs.splunk.com/Documentation/Splunk/7.1.1/Search/Aboutsubsearches
Does sub search help here?
http://docs.splunk.com/Documentation/Splunk/7.1.1/Search/Aboutsubsearches
Exactly what I'm looking for. Thank you very much!
Ok, please accept as answer so that the thread is closed