One more tidbit. I was having a problem with my multi-result subsearch only returning one value (to the main search) when I used the fieldname search. On a lark, I happened to try using the fieldname query (instead of search), and then my subsearch returned more than one value. I've tried and tried to find the difference between search and query mentioned in the documentation somewhere, but (so far) I've not had any luck. (Heck, the documentation for "format" doesn't even mention that it does anything special with fields named search or query - isn't that where it should be mentioned? There is that partial sentence (in the above answer and in the How Subsearches Work section) that says "Multiple results will return" - maybe that sentence was also supposed to mention the use of the fieldname query?)
Sorry - I've only been using Splunk for about a week, so I'm just in the learning phase at the moment. So far, I like Splunk - figuring out how to make use of its power has been the challenging part 🙂 .
... View more