LOGBOOK

HELP

Quiz Entry - updated: 2026.09.24

What is a subsearch in Splunk, and what does sourcetype=syslog [ search login error | return user ] do?

A subsearch is a search in square brackets that runs first and passes its result into the outer search as an argument; this one finds the user who last had a login error and then returns all syslog events of that user.

Subsearch: inner search returns user alice, which replaces the brackets so the outer search finds all syslog events of alice

* Inner first, its result becomes the outer search's filter. *

Execution order:

  1. The inner search search login error | return user runs on its own. return user hands back the user value of the first result, formatted as user="alice".
  2. That text replaces the bracketed part, so the outer search becomes sourcetype=syslog user="alice".
  3. The outer search runs normally.

return gives only one value by default; return 5 user returns up to five, combined with OR.

Subsearches are the SPL answer to "find X, then show me everything about X" without copying values by hand. They have limits (a default time and result cap), so for joining large data sets stats over both data sets is usually the better choice.

Go deeper:

From Quiz: ITIA / Logging Lab: Sysmon, Splunk and the Elastic Stack | Updated: Sep 24, 2026