To filter data after aggregation, use the HAVING clause.A subsearch is a nested search within a primary (outer) search, enclosed in square brackets [ ].Performance considerations: Subsearches are limited to 10,000 results and 60 seconds by default.The append command in Splunk appends the results of a subsearch to the main search results.