Hi, This seems super dumb, but I've been fiddling with this for an embarrassingly long time now. It's been a couple of years since I've written any sub-searches. I'm attempting to project data from the subqueries into a summary table (all from the same root search results) This is running on splunk cloud under a trial license. See dumbed down queries belong. Happily returns a result: index=xxx
| search index=xxx admintom | stats count as x | table x
| table x Format returns nothing (`format` shows `NOT()`) index=xxx
[ search index=xxx admintom | stats count as x | table x ]
| table x
... View more