Splunk Search

query a field with result from another query

Cbr1sg
Path Finder

Hello all,
I have query1 looks like below:

<query1> | fields dialog1 | table dialog1

I want to have query2 to search for all events that field Dialog matches results from query1, something like below:

index=abc Dialog=dialog1

Problem is there could be more than 1 value of dialog1, how can I compare them one by one with Dialog?

I know the join command can work in this case, by first doing index=abc and then filtering out the result by joining the 2 queries together via Dialog field. However this is no good as there would be too much of data if I search by index=abc alone.

Anyone knows a better way to do this? Thanks

Tags (2)
0 Karma
1 Solution

renjith_nair
Legend
0 Karma

renjith_nair
Legend
0 Karma

Cbr1sg
Path Finder

Exactly what I'm looking for. Thank you very much!

0 Karma

renjith_nair
Legend

Ok, please accept as answer so that the thread is closed

Happy Splunking!
0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...