When creating an event type in Splunk, subsearches are allowed in the search string. Subsearches enable users to perform a secondary search whose results are used as input for the main search. This functionality is useful for more complex event type definitions that require additional filtering or criteria based on another search.
[References:, Splunk Docs: About subsearches, Splunk Docs: Event type creation, Splunk Answers: Using subsearches in event types, , , ]
Submit