November 12, 2021

Sub-search or Sub-query in Splunk

search command can be used for sub-search or sub query in Splunk. search command should be within [].
 
Syntax:
main query [search subquery]

Sample Query:
index=abc type=test
[search index=abc *Exception* source=G
earliest=-5d | table requestId] earliest=-5d


Note:
***Sub-search will run first

No comments:

Post a Comment