Splunk Search

subsearch semantics

igorbukanov
Engager

I was trying to figure out why my search with subsearch does not work and then I realized that exact semantics of the subsearch is not clear for me.

Consider the following search:

( ( t="*my_substring*" ) )

This works and generates a number of results. Then consider the following search:

*| eval t="*my_substring*" | head 1 | fields t | format

It generates:

( ( t="*my_substring*" ) )

That is, I got the same text that I used for the first search. Now I combine both:

[search *| eval t="*my_substring*" | head 1 | fields t]

This gives 0 results. Why? I thought the subsearch result are formated using an implicit format and then the outer search is running with [...] literally replaced with that result string.

Tags (1)

reed_kelly
Contributor

I didn't have a problem with it. I also changed the search to use gentimes for performance reasons (it doesn't need to hit indexes). Here is my subquery example:

index=_internal [gentimes start=1/1/00 end=1/2/00|eval user="*kelly*"|fields user]
0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...