I am trying to use a subsearch on another search but not sure how to format it properly
eventtype=pan (https://link1.net OR https://link2.net OR https://link3.net)| rex field=url "LEN_(?<serial>\w+)"| fillnull value=NULL src_bunit, serial| fields src_bunit| dedup src_bunit| mvcombine src_bunit delim=","| nomv src_bunit | format
The syntax shown from the format command is:
( src_bunit="A,B,C,D,E,F" ) )
On the main search I get this error:
Error in 'search' command: Unable to parse the search: Right hand side of IN must be a collection of literals.
The main search
eventtype=dsp_inventory device_control_tags="IMPORTANT*" code IN([subsearch)
My question is how can a format the subsearch in a way that on the main search it will show results like?:
A,B,C,D,E,F instead of src_bunit="A,B,C,D,E,F"
Any ideas? Thank you!
Replace the 'format' command with
that will return A,B,C,D,E,F
View solution in original post
That did it. Thanks a lot. You sir are a God!