Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Trying to use subsearch to filter records

$
0
0
Looking at event data to run some eval commands... specifically on records with any "Status" value. Then once I get those events eval's done and narrowed down, I want to only see the events with Status!=Closed. So how can I look at ALL events at the front-end of the query, then filter down to a specific xxx=yyy at the back-half of the query? Mind has melted... ha thanks! joe

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>