In some situations, you may need to utilize one of the more complex commands, such as sub-searches, join, or transaction. These commands allow you to handle dynamic events and values that would otherwise be difficult or impossible to do within a single search.
Advanced search commands
Subsearches
A subsearch is a search that runs within a primary, or outer, search, and is intended to return results to the primary/outer search to provide data that the primary search needs.
When a search contains a subsearch, the subsearch is run first. Subsearches must be enclosed in square brackets in the primary search, and the first term must be an event-generating command such as search, eventcount, or tstats (usually, you'll use search...