I am battling with the use of the map search command.
I have some queries that work fine by themselves, but when I try and combine them I get an error in the form: "Unable to run query XXX"
However, if I copy the quoted query that Splunk is "unable to run" and paste it into a new search by itself it runs without any problems.
The command I am using is:
sourcetype="WinEventLog:Application" "not known to the TermApp" | rex field=_raw "terminal ID (?<TID>.*) is not known" | lookup terminal_lookup TID OUTPUT PTID | stats count by PTID | search count>50 | map maxsearches=17 search="sourcetype="vc_termlog" TermID=$PTID$"