Extend and branch SPL2 search statements

A powerful feature of modules is the ability to create and extend or branch a base search. A base search applies filters to events to curate the events into a useful set of search results. From there you can extend or branch the base search by adding more filters or by applying commands to summarize or transform the search results.

This image shows two diagrams. The first diagram shows a base search with two consecutive child searches. The second diagram shows a base search and two parallel branch searches.

You can combine extending and branching either from the same base search, or from a child or branch search in your module.

Extending a base search

Branching a base search