Splunk Search

subsearch matching latest

rj1
Engager

I'm trying to create a query that basically says:

 

Show me events that contain A, B, C or D where the latest is A or B.

 

I believe I  could do this with a subsearch:

"A" or "B" randomfield=X [search ("A" or "B" or "C" or "D") randomfield=X | head 1]

I know the first part pulls the right data, and the 2nd part pulls the right data, I just can't get them both to return the one result that I want.

 

I also tried this as a transaction:

"A" OR "C"randomfield=X | transaction startswith="A" endswith="C" keepevicted=t | search closed_txn=0 | stats count by randomField

 

But I realized there are more than just one possible start and one possible end.

 

I just want to make sure that the LAST result from a list of specific events is a smaller list of specific events.

 

Thanks!

Labels (1)
0 Karma
1 Solution

rj1
Engager

I got it working with something like:

("A" OR "B") randomField=*X* | join [search randomField=*X* ("A"  OR "B" OR "C" OR "D") | dedup randomField] table randomField _time

View solution in original post

rj1
Engager

I got it working with something like:

("A" OR "B") randomField=*X* | join [search randomField=*X* ("A"  OR "B" OR "C" OR "D") | dedup randomField] table randomField _time

richgalloway
SplunkTrust
SplunkTrust

Whenever you work with a subsearch and don't get the results you expect, start by running the subsearch by itself with | format appended to it.  That result will be tacked on to the end of whatever came before the subsearch and run as if you had typed it that way. That should help determine if the subsearch is doing what you want.

---
If this reply helps you, Karma would be appreciated.
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...