Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Use subsearch with stats command to dynamically search for list of events

$
0
0
|inputlookup test_results |where build == [|inputlookup test|stats first(build)] I'm trying to do something like the above. ie find the latest build number in the csv lookup file that gets created as part of an earlier base search and then find all events with that build number. I get the following "Error in 'where' command: Typechecking failed. The '==' operator received different types." The build field is a number in the csv file (ie no quotes) and looks ok when I just run the stats command. Same with the search ie when I hardcode the build number it return the correct results. So I think it's something to do with how subsearches return values but don't know how to deal with this. Thanks in advance for any help

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>