Branch SPL2 searches

A powerful feature of modules is the ability to create and branch a base search. A base search applies filters to events to curate the events into a useful set of search results. From there you can branch the base search by adding more filters or by applying commands to summarize or transform the search results.

There are 2 types of branches. You can create a set of cascading child searches or create parallel branch searches, as shown in the following diagram: This image shows two diagrams. The first diagram shows a base search with two consecutive child searches. The second diagram shows a base search and two parallel branch searches.

These 2 types of branch searches are not mutually exclusive. You can combine child searches with parallel branch searches off the same base search.

Example of cascading child searches

Example of parallel branch searches