Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How to use the output from one search as input for another search?

$
0
0
I have a search that results in an IP address as the result with the field name **clientIP**: host=hostname SSL=TLSv1.2 | stats count by clientIP Now I want to take the results and use as a search using the same values for **clientIP**, renamed as **RequestIP**, such that I'm using the IP addresses from the initial result and using that to count addresses: host=hostname2 RequestIP | stats count by task

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>