Splunk : Discussion on "Subsearches"

Поделиться
HTML-код
  • Опубликовано: 25 ноя 2024

Комментарии • 17

  • @securiosityy
    @securiosityy Год назад

    Very well explained! I just couldn't understand why anyone would use sub searches. This makes much more sense now. Thank you!

  • @VadersWeekendHelmet
    @VadersWeekendHelmet 2 года назад +1

    I'm already 10 mins in and learned a lot. Subsearch was something I could never fully master even after year of using Splunk, but thanks for the video packed full of info!

  • @wondl6608
    @wondl6608 4 года назад +3

    Thank you so much for the outstanding videos. I learned a lot from you . Thank you much !! Well explained and to the point . Any plans releasing videos on Splunk Enterprise security and ITSI.
    Thanks
    All the best

    • @splunk_ml
      @splunk_ml  4 года назад +3

      Thank you... Only thing is stopping me to cover itsi is its not free... And 7 days of sandbox is not enough... I sent an email to splunk but I don't think they will entertain my request for longer sandbox. I am thinking to cover the theory part first then use the sandbox for some demo

  • @vipulsoman
    @vipulsoman Год назад

    Learnt a lot from your video, thank you

  • @vikashperiwal1498
    @vikashperiwal1498 4 года назад

    Nice explanation with a beautiful use case...

  • @HipHopHoller
    @HipHopHoller 4 года назад

    Outstanding video. Thank you!

  • @etaihellman4591
    @etaihellman4591 2 года назад

    Amazing video!! Thank you again.!!

  • @dth546
    @dth546 3 года назад

    Thanks for the video. It helped me.

  • @hectorcrespo1747
    @hectorcrespo1747 3 года назад

    Thanks, very useful video

  • @donneakaleath9131
    @donneakaleath9131 3 года назад

    Thank you!

  • @vikassingh4320
    @vikassingh4320 4 года назад

    The Best.. As always

  • @venunair8337
    @venunair8337 4 года назад

    can you pls....start Splunk Enterprise security your videos are awesome

  • @raju5081
    @raju5081 3 года назад

    Very good video. I have one question - For e.g. :
    Subsearch gives few accountIDs from different index and sourcetype. (Contains only order info)
    Main search needs those accountIDs to filter them out and show inactive accountIDs that did not place any orders yet
    Subsearch - has order info
    MainSearch - has account info
    index=account sourcetype=x NOT [ index=order sourcetype=y | fields accountID ] | table accountID
    is the above query correct ? what is the fastest way to get it ?

    • @splunk_ml
      @splunk_ml  3 года назад

      Yes the query looks correct. Fastest way would be if you can build a summary from the query result and use summary index in your reports or dashboards.