<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Search with passed variable (like ldapfilter search=&amp;quot;(samaccountname=$user$)&amp;quot;) doesn't work when in simple in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Search-with-passed-variable-like-ldapfilter-search-quot/m-p/576616#M47249</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/80712"&gt;@rupeters&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;$$ did the trick for me.&lt;/P&gt;&lt;P&gt;(samaccountname=$$user$$)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 29 Nov 2021 13:17:30 GMT</pubDate>
    <dc:creator>peppi</dc:creator>
    <dc:date>2021-11-29T13:17:30Z</dc:date>
    <item>
      <title>Search with passed variable (like ldapfilter search="(samaccountname=$user$)") doesn't work when in simple XML</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Search-with-passed-variable-like-ldapfilter-search-quot/m-p/186578#M11570</link>
      <description>&lt;P&gt;I have a search that works fine:&lt;/P&gt;

&lt;P&gt;[search that returns a list of users in a user variable] | domain=MYDOMAIN search="(samaccountname=$user$)ldapfilter" attrs="cn,dn,displayName"&lt;BR /&gt;
works great in search. But when I put the search in a form (simple xml) I get an error, "Search query is not fully resolved."&lt;/P&gt;

&lt;P&gt;It appears that the $user$ variable is being interpreted as a token. I've tried to escape $user$ as \$user\$, but that doesn't work. Please help.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Dec 2013 13:02:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Search-with-passed-variable-like-ldapfilter-search-quot/m-p/186578#M11570</guid>
      <dc:creator>rupeters</dc:creator>
      <dc:date>2013-12-20T13:02:18Z</dc:date>
    </item>
    <item>
      <title>Re: Search with passed variable (like ldapfilter search="(samaccountname=$user$)") doesn't work when in simple XML</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Search-with-passed-variable-like-ldapfilter-search-quot/m-p/186579#M11571</link>
      <description>&lt;P&gt;Tried to edit the above. It won't let me. What I wanted to say was "I've tried to escape $user$ as \$user\$"&lt;/P&gt;</description>
      <pubDate>Fri, 20 Dec 2013 13:16:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Search-with-passed-variable-like-ldapfilter-search-quot/m-p/186579#M11571</guid>
      <dc:creator>rupeters</dc:creator>
      <dc:date>2013-12-20T13:16:02Z</dc:date>
    </item>
    <item>
      <title>Re: Search with passed variable (like ldapfilter search="(samaccountname=$user$)") doesn't work when in simple XML</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Search-with-passed-variable-like-ldapfilter-search-quot/m-p/186580#M11572</link>
      <description>&lt;P&gt;Tried \$\$user\$\$ ? I seem to recall having to do that in another context.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Dec 2013 16:21:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Search-with-passed-variable-like-ldapfilter-search-quot/m-p/186580#M11572</guid>
      <dc:creator>sowings</dc:creator>
      <dc:date>2013-12-20T16:21:50Z</dc:date>
    </item>
    <item>
      <title>Re: Search with passed variable (like ldapfilter search="(samaccountname=$user$)") doesn't work when in simple XML</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Search-with-passed-variable-like-ldapfilter-search-quot/m-p/186581#M11573</link>
      <description>&lt;P&gt;Figured out a workaround to the problem by putting the above search into a macro (macroname) and calling the macro from the &lt;SEARCHSTRING&gt;&lt;CODE&gt;macroname&lt;/CODE&gt;&lt;/SEARCHSTRING&gt; in the form.&lt;/P&gt;</description>
      <pubDate>Sat, 21 Dec 2013 23:13:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Search-with-passed-variable-like-ldapfilter-search-quot/m-p/186581#M11573</guid>
      <dc:creator>rupeters</dc:creator>
      <dc:date>2013-12-21T23:13:23Z</dc:date>
    </item>
    <item>
      <title>Re: Search with passed variable (like ldapfilter search="(samaccountname=$user$)") doesn't work when in simple</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Search-with-passed-variable-like-ldapfilter-search-quot/m-p/576616#M47249</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/80712"&gt;@rupeters&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;$$ did the trick for me.&lt;/P&gt;&lt;P&gt;(samaccountname=$$user$$)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Nov 2021 13:17:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Search-with-passed-variable-like-ldapfilter-search-quot/m-p/576616#M47249</guid>
      <dc:creator>peppi</dc:creator>
      <dc:date>2021-11-29T13:17:30Z</dc:date>
    </item>
  </channel>
</rss>

