Splunk subsearch for regex outputs












0















I want a single search query for below splunk query.



First search will give me a dynamic field myorderid



index=mylog "trigger.rule: Id - * : Unexpected System Error" | rex field=_raw "Id -""(?[^:]*)" | table myorderid



I want to pass the above myorderid in below search criteria



index=mylog API=Order orderid=myorderid



Can anyone please help me to create a single query using subsearch in splunk.










share|improve this question



























    0















    I want a single search query for below splunk query.



    First search will give me a dynamic field myorderid



    index=mylog "trigger.rule: Id - * : Unexpected System Error" | rex field=_raw "Id -""(?[^:]*)" | table myorderid



    I want to pass the above myorderid in below search criteria



    index=mylog API=Order orderid=myorderid



    Can anyone please help me to create a single query using subsearch in splunk.










    share|improve this question

























      0












      0








      0








      I want a single search query for below splunk query.



      First search will give me a dynamic field myorderid



      index=mylog "trigger.rule: Id - * : Unexpected System Error" | rex field=_raw "Id -""(?[^:]*)" | table myorderid



      I want to pass the above myorderid in below search criteria



      index=mylog API=Order orderid=myorderid



      Can anyone please help me to create a single query using subsearch in splunk.










      share|improve this question














      I want a single search query for below splunk query.



      First search will give me a dynamic field myorderid



      index=mylog "trigger.rule: Id - * : Unexpected System Error" | rex field=_raw "Id -""(?[^:]*)" | table myorderid



      I want to pass the above myorderid in below search criteria



      index=mylog API=Order orderid=myorderid



      Can anyone please help me to create a single query using subsearch in splunk.







      search splunk splunk-query






      share|improve this question













      share|improve this question











      share|improve this question




      share|improve this question










      asked Nov 23 '18 at 11:55









      Gaurav AgrahariGaurav Agrahari

      1




      1
























          1 Answer
          1






          active

          oldest

          votes


















          1














          Have you tried the obvious?



          index=mylog API=Order orderid=
          [ search index=mylog "trigger.rule: Id - * : Unexpected System Error"
          | rex "Id - (?<myorderid>[^:]*)" | fields myorderid ]





          share|improve this answer























            Your Answer






            StackExchange.ifUsing("editor", function () {
            StackExchange.using("externalEditor", function () {
            StackExchange.using("snippets", function () {
            StackExchange.snippets.init();
            });
            });
            }, "code-snippets");

            StackExchange.ready(function() {
            var channelOptions = {
            tags: "".split(" "),
            id: "1"
            };
            initTagRenderer("".split(" "), "".split(" "), channelOptions);

            StackExchange.using("externalEditor", function() {
            // Have to fire editor after snippets, if snippets enabled
            if (StackExchange.settings.snippets.snippetsEnabled) {
            StackExchange.using("snippets", function() {
            createEditor();
            });
            }
            else {
            createEditor();
            }
            });

            function createEditor() {
            StackExchange.prepareEditor({
            heartbeatType: 'answer',
            autoActivateHeartbeat: false,
            convertImagesToLinks: true,
            noModals: true,
            showLowRepImageUploadWarning: true,
            reputationToPostImages: 10,
            bindNavPrevention: true,
            postfix: "",
            imageUploader: {
            brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
            contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
            allowUrls: true
            },
            onDemand: true,
            discardSelector: ".discard-answer"
            ,immediatelyShowMarkdownHelp:true
            });


            }
            });














            draft saved

            draft discarded


















            StackExchange.ready(
            function () {
            StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53446260%2fsplunk-subsearch-for-regex-outputs%23new-answer', 'question_page');
            }
            );

            Post as a guest















            Required, but never shown

























            1 Answer
            1






            active

            oldest

            votes








            1 Answer
            1






            active

            oldest

            votes









            active

            oldest

            votes






            active

            oldest

            votes









            1














            Have you tried the obvious?



            index=mylog API=Order orderid=
            [ search index=mylog "trigger.rule: Id - * : Unexpected System Error"
            | rex "Id - (?<myorderid>[^:]*)" | fields myorderid ]





            share|improve this answer




























              1














              Have you tried the obvious?



              index=mylog API=Order orderid=
              [ search index=mylog "trigger.rule: Id - * : Unexpected System Error"
              | rex "Id - (?<myorderid>[^:]*)" | fields myorderid ]





              share|improve this answer


























                1












                1








                1







                Have you tried the obvious?



                index=mylog API=Order orderid=
                [ search index=mylog "trigger.rule: Id - * : Unexpected System Error"
                | rex "Id - (?<myorderid>[^:]*)" | fields myorderid ]





                share|improve this answer













                Have you tried the obvious?



                index=mylog API=Order orderid=
                [ search index=mylog "trigger.rule: Id - * : Unexpected System Error"
                | rex "Id - (?<myorderid>[^:]*)" | fields myorderid ]






                share|improve this answer












                share|improve this answer



                share|improve this answer










                answered Nov 23 '18 at 23:53









                RichGRichG

                7261410




                7261410






























                    draft saved

                    draft discarded




















































                    Thanks for contributing an answer to Stack Overflow!


                    • Please be sure to answer the question. Provide details and share your research!

                    But avoid



                    • Asking for help, clarification, or responding to other answers.

                    • Making statements based on opinion; back them up with references or personal experience.


                    To learn more, see our tips on writing great answers.




                    draft saved


                    draft discarded














                    StackExchange.ready(
                    function () {
                    StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53446260%2fsplunk-subsearch-for-regex-outputs%23new-answer', 'question_page');
                    }
                    );

                    Post as a guest















                    Required, but never shown





















































                    Required, but never shown














                    Required, but never shown












                    Required, but never shown







                    Required, but never shown

































                    Required, but never shown














                    Required, but never shown












                    Required, but never shown







                    Required, but never shown







                    Popular posts from this blog

                    Berounka

                    Fiat S.p.A.

                    Type 'String' is not a subtype of type 'int' of 'index'