In this chapter, we will work through a few advanced search examples in great detail. The examples and data shown are fictitious, but hopefully will spark some ideas that you can apply to your own data. For a huge collection of examples and help topics, check out Splunk answers at http://answers.splunk.com.
The number of use cases for subsearches in the real world might be small, but for those situations where they can be applied, subsearches can be a magic bullet. Let's look at an example and then talk about some rules.
Let's start with these events:
2012-04-20 13:07:03 msgid=123456 firstname.lastname@example.org 2012-04-20 13:07:04 msgid=654321 email@example.com ...