<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Add a comment to a search? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Add-a-comment-to-a-search/m-p/60180#M14814</link>
    <description>&lt;P&gt;Nice. This looks like the least work for Splunk to do as part of a search&lt;/P&gt;</description>
    <pubDate>Fri, 25 May 2012 14:21:17 GMT</pubDate>
    <dc:creator>Jason</dc:creator>
    <dc:date>2012-05-25T14:21:17Z</dc:date>
    <item>
      <title>Add a comment to a search?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Add-a-comment-to-a-search/m-p/60167#M14801</link>
      <description>&lt;P&gt;I'm working on a really large search right now (on the order of 35 lines long). Is there a good way to insert a comment into a search query to remind a future search editor what is going on?&lt;/P&gt;

&lt;P&gt;There doesn't seem to be a &lt;CODE&gt;| comment&lt;/CODE&gt; command. &lt;/P&gt;

&lt;P&gt;perhaps &lt;CODE&gt;| rex field=bogus "This could be a comment"&lt;/CODE&gt; ?&lt;/P&gt;</description>
      <pubDate>Thu, 24 May 2012 14:11:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Add-a-comment-to-a-search/m-p/60167#M14801</guid>
      <dc:creator>Jason</dc:creator>
      <dc:date>2012-05-24T14:11:49Z</dc:date>
    </item>
    <item>
      <title>Re: Add a comment to a search?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Add-a-comment-to-a-search/m-p/60168#M14802</link>
      <description>&lt;P&gt;That's a pretty cool idea!  Today, I don't think there is any such mechanism, and I wouldn't recommend using rex as such &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 May 2012 15:31:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Add-a-comment-to-a-search/m-p/60168#M14802</guid>
      <dc:creator>araitz</dc:creator>
      <dc:date>2012-05-24T15:31:07Z</dc:date>
    </item>
    <item>
      <title>Re: Add a comment to a search?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Add-a-comment-to-a-search/m-p/60169#M14803</link>
      <description>&lt;P&gt;What would you recommend then?&lt;/P&gt;</description>
      <pubDate>Thu, 24 May 2012 16:04:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Add-a-comment-to-a-search/m-p/60169#M14803</guid>
      <dc:creator>Jason</dc:creator>
      <dc:date>2012-05-24T16:04:33Z</dc:date>
    </item>
    <item>
      <title>Re: Add a comment to a search?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Add-a-comment-to-a-search/m-p/60170#M14804</link>
      <description>&lt;P&gt;or maybe &lt;CODE&gt;| rex field=comment "(?#This is a comment)"&lt;/CODE&gt; ?&lt;/P&gt;</description>
      <pubDate>Thu, 24 May 2012 16:06:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Add-a-comment-to-a-search/m-p/60170#M14804</guid>
      <dc:creator>Jason</dc:creator>
      <dc:date>2012-05-24T16:06:26Z</dc:date>
    </item>
    <item>
      <title>Re: Add a comment to a search?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Add-a-comment-to-a-search/m-p/60171#M14805</link>
      <description>&lt;P&gt;I try to use macros when possible and give both the macros and saved searches names that strongly bely what purpose they serve.&lt;/P&gt;</description>
      <pubDate>Thu, 24 May 2012 16:08:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Add-a-comment-to-a-search/m-p/60171#M14805</guid>
      <dc:creator>araitz</dc:creator>
      <dc:date>2012-05-24T16:08:29Z</dc:date>
    </item>
    <item>
      <title>Re: Add a comment to a search?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Add-a-comment-to-a-search/m-p/60172#M14806</link>
      <description>&lt;P&gt;Makes sense. Multiple macros can get very confusing, especially multiple levels of them, to anyone trying to maintain or edit a search. However, the search does have three sections that are repeated, so I will attempt to put that in a single macro.&lt;/P&gt;</description>
      <pubDate>Thu, 24 May 2012 17:14:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Add-a-comment-to-a-search/m-p/60172#M14806</guid>
      <dc:creator>Jason</dc:creator>
      <dc:date>2012-05-24T17:14:01Z</dc:date>
    </item>
    <item>
      <title>Re: Add a comment to a search?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Add-a-comment-to-a-search/m-p/60173#M14807</link>
      <description>&lt;P&gt;But the question of how to best add a comment to a search, in the absence of a &lt;CODE&gt;|comment&lt;/CODE&gt;, is still open.&lt;/P&gt;</description>
      <pubDate>Thu, 24 May 2012 17:14:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Add-a-comment-to-a-search/m-p/60173#M14807</guid>
      <dc:creator>Jason</dc:creator>
      <dc:date>2012-05-24T17:14:09Z</dc:date>
    </item>
    <item>
      <title>Re: Add a comment to a search?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Add-a-comment-to-a-search/m-p/60174#M14808</link>
      <description>&lt;P&gt;Agreed, macros can get pretty confusing and there is no way to in-line comment searches, which would be very cool.&lt;/P&gt;</description>
      <pubDate>Thu, 24 May 2012 17:17:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Add-a-comment-to-a-search/m-p/60174#M14808</guid>
      <dc:creator>araitz</dc:creator>
      <dc:date>2012-05-24T17:17:15Z</dc:date>
    </item>
    <item>
      <title>Re: Add a comment to a search?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Add-a-comment-to-a-search/m-p/60175#M14809</link>
      <description>&lt;P&gt;There is one way that does work and it's pretty simple. Place a rename function at the very end of the search and put all your comments in one long string inside double quotes. Here is the end of a 21 line search followed by a comment:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| table Servers,Access_Status,Access,TM,TD,TDB,MB
| rename comment AS "This is a comment. 
1. The search should run
2. none of this comment should show"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The search runs but the comment does not show.&lt;/P&gt;</description>
      <pubDate>Thu, 24 May 2012 20:02:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Add-a-comment-to-a-search/m-p/60175#M14809</guid>
      <dc:creator>kmattern</dc:creator>
      <dc:date>2012-05-24T20:02:24Z</dc:date>
    </item>
    <item>
      <title>Re: Add a comment to a search?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Add-a-comment-to-a-search/m-p/60176#M14810</link>
      <description>&lt;P&gt;Clever!  I like it.&lt;/P&gt;</description>
      <pubDate>Thu, 24 May 2012 20:03:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Add-a-comment-to-a-search/m-p/60176#M14810</guid>
      <dc:creator>araitz</dc:creator>
      <dc:date>2012-05-24T20:03:10Z</dc:date>
    </item>
    <item>
      <title>Re: Add a comment to a search?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Add-a-comment-to-a-search/m-p/60177#M14811</link>
      <description>&lt;P&gt;...and then make a long search even longer &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 25 May 2012 00:21:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Add-a-comment-to-a-search/m-p/60177#M14811</guid>
      <dc:creator>_d_</dc:creator>
      <dc:date>2012-05-25T00:21:18Z</dc:date>
    </item>
    <item>
      <title>Re: Add a comment to a search?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Add-a-comment-to-a-search/m-p/60178#M14812</link>
      <description>&lt;P&gt;We use a SVN repository to document all our Splunk queries we have in production.&lt;/P&gt;</description>
      <pubDate>Fri, 25 May 2012 11:41:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Add-a-comment-to-a-search/m-p/60178#M14812</guid>
      <dc:creator>lpolo</dc:creator>
      <dc:date>2012-05-25T11:41:46Z</dc:date>
    </item>
    <item>
      <title>Re: Add a comment to a search?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Add-a-comment-to-a-search/m-p/60179#M14813</link>
      <description>&lt;P&gt;I complained to my SE about this.  He sugested:&lt;/P&gt;

&lt;P&gt;| eval commnet="This is a comment"&lt;/P&gt;</description>
      <pubDate>Fri, 25 May 2012 13:03:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Add-a-comment-to-a-search/m-p/60179#M14813</guid>
      <dc:creator>fk319</dc:creator>
      <dc:date>2012-05-25T13:03:28Z</dc:date>
    </item>
    <item>
      <title>Re: Add a comment to a search?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Add-a-comment-to-a-search/m-p/60180#M14814</link>
      <description>&lt;P&gt;Nice. This looks like the least work for Splunk to do as part of a search&lt;/P&gt;</description>
      <pubDate>Fri, 25 May 2012 14:21:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Add-a-comment-to-a-search/m-p/60180#M14814</guid>
      <dc:creator>Jason</dc:creator>
      <dc:date>2012-05-25T14:21:17Z</dc:date>
    </item>
    <item>
      <title>Re: Add a comment to a search?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Add-a-comment-to-a-search/m-p/60181#M14815</link>
      <description>&lt;P&gt;I would think it uses fewer clocks than the eval.&lt;/P&gt;</description>
      <pubDate>Fri, 25 May 2012 14:24:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Add-a-comment-to-a-search/m-p/60181#M14815</guid>
      <dc:creator>kmattern</dc:creator>
      <dc:date>2012-05-25T14:24:58Z</dc:date>
    </item>
    <item>
      <title>Re: Add a comment to a search?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Add-a-comment-to-a-search/m-p/60182#M14816</link>
      <description>&lt;P&gt;This would be wasteful for large result sets, as it would create a 'comment' field for each result.&lt;/P&gt;</description>
      <pubDate>Fri, 25 May 2012 14:46:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Add-a-comment-to-a-search/m-p/60182#M14816</guid>
      <dc:creator>araitz</dc:creator>
      <dc:date>2012-05-25T14:46:43Z</dc:date>
    </item>
    <item>
      <title>Re: Add a comment to a search?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Add-a-comment-to-a-search/m-p/60183#M14817</link>
      <description>&lt;P&gt;The rename looks better...&lt;/P&gt;</description>
      <pubDate>Fri, 25 May 2012 14:53:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Add-a-comment-to-a-search/m-p/60183#M14817</guid>
      <dc:creator>fk319</dc:creator>
      <dc:date>2012-05-25T14:53:11Z</dc:date>
    </item>
    <item>
      <title>Re: Add a comment to a search?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Add-a-comment-to-a-search/m-p/60184#M14818</link>
      <description>&lt;P&gt;If the comment supposed to be always the same per category : the best thing seems to create a lookup on a field (like error field), that has 2 columns "error", "comment" and apply the lookup at the end of your search to add the comment. Then you just have to maintain the lookup table.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Dec 2012 12:17:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Add-a-comment-to-a-search/m-p/60184#M14818</guid>
      <dc:creator>commerinesong</dc:creator>
      <dc:date>2012-12-28T12:17:29Z</dc:date>
    </item>
    <item>
      <title>Re: Add a comment to a search?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Add-a-comment-to-a-search/m-p/60185#M14819</link>
      <description>&lt;P&gt;I'd like to make comments an enhancement request for Splunk so that comments could be placed throughout the search without affecting it from the current pipe through the next pipe, both to disable portions of the search that aren't currently being used and to allow comments to be placed inline in the search.  Any of these formats would be sensible: &lt;BR /&gt;
|comment &lt;BR /&gt;
|rem &lt;BR /&gt;
|#&lt;BR /&gt;
or even&lt;BR /&gt;
|&amp;lt;!-- comment --&amp;gt;|&lt;BR /&gt;
for instance:&lt;/P&gt;

&lt;P&gt;index=main source=df &lt;BR /&gt;
|rex field=_raw "(?&lt;DISK&gt;\w\S)\shas\s(?&lt;PCTFREE&gt;\d{1,2})\%\sfree" max_match=10 &lt;BR /&gt;
| eval disk-pctfree = mvzip(disk, pctfree) | mvexpand disk-pctfree |fields host, disk-pctfree | rex field=disk-pctfree "(?&lt;DISK&gt;\w\S),(?&lt;PCTFREE&gt;\d{1,2})" |stats min(pctfree) by host, disk | sort by min(pctfree) | rename min(pctfree) as "Minimum % Free" &lt;BR /&gt;
| search "Minimum % Free"&amp;lt;11&lt;/PCTFREE&gt;&lt;/DISK&gt;&lt;/PCTFREE&gt;&lt;/DISK&gt;&lt;/P&gt;

&lt;P&gt;|comment begin exclusions&lt;BR /&gt;
|search NOT ( host=hostname1 AND disk=D: )&lt;BR /&gt;
|search NOT ( host=hostname2 AND disk=D: )&lt;BR /&gt;
|search NOT ( host=hostname3 AND disk=C: )&lt;BR /&gt;
|comment use this method to set an alternate minimum: search NOT ( host=hostname4 AND disk=E: AND "Minimum % Free"&amp;gt;5 )&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 13:34:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Add-a-comment-to-a-search/m-p/60185#M14819</guid>
      <dc:creator>edonze</dc:creator>
      <dc:date>2020-09-28T13:34:22Z</dc:date>
    </item>
    <item>
      <title>Re: Add a comment to a search?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Add-a-comment-to-a-search/m-p/60186#M14820</link>
      <description>&lt;P&gt;The html style comment did not parse properly.  It shows up as two pipes instead of pipe less than bang dash dash comment dash dash greater than pipe.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Mar 2013 17:18:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Add-a-comment-to-a-search/m-p/60186#M14820</guid>
      <dc:creator>edonze</dc:creator>
      <dc:date>2013-03-21T17:18:24Z</dc:date>
    </item>
  </channel>
</rss>

