A **subsearch** is a search that is enclosed in square brackets `[]` and executed before the main (outer) search.
The results of the subsearch are evaluated, formatted as a search string, and passed back into the outer search.
sourcetype=access_combined
[ search status=500 | return 1 clientip ]