Splunk Search

order of sub searches changed when using saved search or the summary page

mataharry
Communicator

in 4.1.6 On the UI, I can run a search with a sub search in the condition.

index="_internal" source="log" OR [ search index=_internal source="etrics" | head 2 |table source ] | table source

But when I save it and call it from the "saved search" menu. Or that I type it on the summary page, on the result page, all got wrong because the order changed.

the [ search ...] block is now at the beginning of the line

[ search index=_internal source="etrics" | head 2 |table source ] index="_internal" source="log" OR | table source

Tags (2)
1 Solution

Genti
Splunk Employee
Splunk Employee

This was brought to support's attention last week. It's an intentions issue and this behavior is already fixed on 4.2
Perhaps it will also be fixed in the next maintenance release, you could try creating a case with support so that your issue gets logged as well.

Cheers

View solution in original post

Genti
Splunk Employee
Splunk Employee

This was brought to support's attention last week. It's an intentions issue and this behavior is already fixed on 4.2
Perhaps it will also be fixed in the next maintenance release, you could try creating a case with support so that your issue gets logged as well.

Cheers

mataharry
Communicator

thanks Genti Sama.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...