When creating an event type, which is allowed in the search string?
When creating an event type in Splunk, subsearches are allowed in the search string. Subsearches enable users to perform a secondary search whose results are used as input for the main search. This functionality is useful for more complex event type definitions that require additional filtering or criteria based on another search.
Splunk Docs: About subsearches
Splunk Docs: Event type creation
Splunk Answers: Using subsearches in event types
Alva
2 months agoDaron
2 months agoMerlyn
3 months agoLuisa
3 months agoNatalie
3 months agoAlaine
3 months agoLelia
4 months agoCammy
4 months agoCatarina
4 months agoMarylin
4 months agoPrincess
4 months agoJeff
5 months agoNu
5 months ago