I'm new to Splunk and would like to know if there's a way to create a two level query such as this one below:
SELECT * FROM some_logtype WHERE ID IN (
SELECT distinct KnownID FROM some_logtype WHERE someCondition
)
search
sourcetype=secondlogtype |join ID [search sourcetype=secondlogtype]
You can use index name instead of sourcetype if sourctypes are same and index are differnt.