hello Splunkers!
I've got an issue with this query, in "main search" I got data src, can I use "src" to get data on my "second search".
later on, the final result ignored from "main search "
anyone can help me?
thanks,
index=VPN | table src -> main search [search index=firewall | table src dest_ip] -> second search | table src dest_ip
So, my search should work for you.
Sorry this solution not solving my problem
Hi @taufiqkpi,
I think you want to filter VPN sources from Firewall index, please try below;
search index=firewall NOT
[ index=VPN
| fields src]
| table src dest_ip