|
(Copied from a legacy Splunk Forums post by user Hello I have the following problem:
I have the following search:
The subsearch returns something like: Now, my problem is, that in the different sources the Thanks for your help. Bruno |
|
Yes. Do this:
If the field is named This is a special case only when the field is named either "search" or "query". Renaming your fields to anything else will make the subsearch use the new field names. |
