splunk subquery command: []
example: [search sourcetype=* index=yourIndex subject=”yourSubject” | head 1 | eval day=strftime(_time, “%Y-%m-%d”) | return $day]
it will get a day as a query condition.
refer to: https://docs.splunk.com/Documentation/SplunkCloud/latest/SearchReference/Return