There are various kinds of advanced searches you may need as you plan out how to create searches and dashboards for your data. Consider the ones that we present, for they will help you design queries that are more efficient and cost effective.
Advanced searches
Subsearch
A subsearch is a search within a search. If your main search requires data as a result of another search, use Splunk's subsearch capability to combine two searches into one.
Say you want to find statistics about the server that generates the most HTTP status 500 errors. You can achieve your goal of finding the culprit server with two searches.
The first search, shown next, will return the server address with the most 500 errors. Note that you are setting...