Friday, January 16, 2015

Splunk subsearch where you want it to only return a single value

By default a Splunk subsearch returns something of the form “fieldname=24″. If you only want it to return the “24” part, just name the field in the subsearch “query”. Yeah, it’s a magic term for just such a scenario.





No comments:

Post a Comment