<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to add dynamic value in search query? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-add-dynamic-value-in-search-query/m-p/642867#M222652</link>
    <description>&lt;P&gt;I have created a post curl to add data in Splunk, internally my api hits Splunk api and in that api I send data in body &amp;amp; that data would get created in my splunk table.&lt;BR /&gt;I want to add dynamic value in search query of splunk api.&lt;BR /&gt;How can i achieve that, please help here&lt;/P&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;method&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;"POST"&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;path&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;"/api/addSplunk"&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;handler&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;async&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN&gt;request&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;h&lt;/SPAN&gt;&lt;SPAN&gt;) &lt;/SPAN&gt;&lt;SPAN&gt;=&amp;gt;&lt;/SPAN&gt;&lt;SPAN&gt; {&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;const&lt;/SPAN&gt; &lt;SPAN&gt;ccmData&lt;/SPAN&gt;&lt;SPAN&gt; = &lt;/SPAN&gt;&lt;SPAN&gt;getServerConfig&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN&gt;request&lt;/SPAN&gt;&lt;SPAN&gt;);&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;const&lt;/SPAN&gt; &lt;SPAN&gt;url&lt;/SPAN&gt;&lt;SPAN&gt; =&lt;/SPAN&gt; &lt;SPAN&gt;ccmData&lt;/SPAN&gt;&lt;SPAN&gt;[&lt;/SPAN&gt;&lt;SPAN&gt;"splunkApiUrl"&lt;/SPAN&gt;&lt;SPAN&gt;];&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;const ChannelName= request.payload.channel_name;&amp;nbsp; // I want to use this value in search query&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;const Channel= request.payload.channel_type;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;function&lt;/SPAN&gt; &lt;SPAN&gt;xmlTranslate&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN&gt;resp&lt;/SPAN&gt;&lt;SPAN&gt;) {&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;return&lt;/SPAN&gt; &lt;SPAN&gt;resp&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;SPAN&gt;text&lt;/SPAN&gt;&lt;SPAN&gt;()&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;}&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;const&lt;/SPAN&gt; &lt;SPAN&gt;httpsAgent&lt;/SPAN&gt;&lt;SPAN&gt; = &lt;/SPAN&gt;&lt;SPAN&gt;new&lt;/SPAN&gt; &lt;SPAN&gt;https&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;SPAN&gt;Agent&lt;/SPAN&gt;&lt;SPAN&gt;({&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;rejectUnauthorized&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;false&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;});&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;SPAN&gt;const&lt;/SPAN&gt; &lt;SPAN&gt;options&lt;/SPAN&gt;&lt;SPAN&gt; = {&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;method&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;"POST"&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;headers&lt;/SPAN&gt;&lt;SPAN&gt;: {&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;"Authorization"&lt;/SPAN&gt;&lt;SPAN&gt;: "dr356654fy6&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;"Content-Type"&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;"application/x-www-form-urlencoded"&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;},&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;agent&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;httpsAgent&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;translate&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;xmlTranslate&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;body&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;'search=| makeresults | &lt;STRONG&gt;eval Channel ="372864u31564719" | eval ChannelName = "4P customer"&lt;/STRONG&gt; | table Channel,ChannelName | outputlookup channel.csv append=true'&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;};&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;const&lt;/SPAN&gt; &lt;SPAN&gt;res&lt;/SPAN&gt;&lt;SPAN&gt; = &lt;/SPAN&gt;&lt;SPAN&gt;await&lt;/SPAN&gt; &lt;SPAN&gt;fetch&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN&gt;url&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;options&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;xmlTranslate&lt;/SPAN&gt;&lt;SPAN&gt;);&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;Right now I have hardcoded like this&amp;nbsp;&lt;SPAN&gt;&lt;STRONG&gt;eval Channel ="372864u31564719" |&amp;nbsp;eval ChannelName = "4P customer", &lt;/STRONG&gt;I want to add dynamic value for diff use case in channel and channelName of search query (i.e coming from&lt;STRONG&gt; request payload)&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/DIV&gt;</description>
    <pubDate>Thu, 11 May 2023 02:07:05 GMT</pubDate>
    <dc:creator>s0k0</dc:creator>
    <dc:date>2023-05-11T02:07:05Z</dc:date>
    <item>
      <title>How to add dynamic value in search query?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-add-dynamic-value-in-search-query/m-p/642867#M222652</link>
      <description>&lt;P&gt;I have created a post curl to add data in Splunk, internally my api hits Splunk api and in that api I send data in body &amp;amp; that data would get created in my splunk table.&lt;BR /&gt;I want to add dynamic value in search query of splunk api.&lt;BR /&gt;How can i achieve that, please help here&lt;/P&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;method&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;"POST"&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;path&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;"/api/addSplunk"&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;handler&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;async&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN&gt;request&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;h&lt;/SPAN&gt;&lt;SPAN&gt;) &lt;/SPAN&gt;&lt;SPAN&gt;=&amp;gt;&lt;/SPAN&gt;&lt;SPAN&gt; {&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;const&lt;/SPAN&gt; &lt;SPAN&gt;ccmData&lt;/SPAN&gt;&lt;SPAN&gt; = &lt;/SPAN&gt;&lt;SPAN&gt;getServerConfig&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN&gt;request&lt;/SPAN&gt;&lt;SPAN&gt;);&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;const&lt;/SPAN&gt; &lt;SPAN&gt;url&lt;/SPAN&gt;&lt;SPAN&gt; =&lt;/SPAN&gt; &lt;SPAN&gt;ccmData&lt;/SPAN&gt;&lt;SPAN&gt;[&lt;/SPAN&gt;&lt;SPAN&gt;"splunkApiUrl"&lt;/SPAN&gt;&lt;SPAN&gt;];&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;const ChannelName= request.payload.channel_name;&amp;nbsp; // I want to use this value in search query&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;const Channel= request.payload.channel_type;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;function&lt;/SPAN&gt; &lt;SPAN&gt;xmlTranslate&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN&gt;resp&lt;/SPAN&gt;&lt;SPAN&gt;) {&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;return&lt;/SPAN&gt; &lt;SPAN&gt;resp&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;SPAN&gt;text&lt;/SPAN&gt;&lt;SPAN&gt;()&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;}&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;const&lt;/SPAN&gt; &lt;SPAN&gt;httpsAgent&lt;/SPAN&gt;&lt;SPAN&gt; = &lt;/SPAN&gt;&lt;SPAN&gt;new&lt;/SPAN&gt; &lt;SPAN&gt;https&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;SPAN&gt;Agent&lt;/SPAN&gt;&lt;SPAN&gt;({&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;rejectUnauthorized&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;false&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;});&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;SPAN&gt;const&lt;/SPAN&gt; &lt;SPAN&gt;options&lt;/SPAN&gt;&lt;SPAN&gt; = {&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;method&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;"POST"&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;headers&lt;/SPAN&gt;&lt;SPAN&gt;: {&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;"Authorization"&lt;/SPAN&gt;&lt;SPAN&gt;: "dr356654fy6&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;"Content-Type"&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;"application/x-www-form-urlencoded"&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;},&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;agent&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;httpsAgent&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;translate&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;xmlTranslate&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;body&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;'search=| makeresults | &lt;STRONG&gt;eval Channel ="372864u31564719" | eval ChannelName = "4P customer"&lt;/STRONG&gt; | table Channel,ChannelName | outputlookup channel.csv append=true'&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;};&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;const&lt;/SPAN&gt; &lt;SPAN&gt;res&lt;/SPAN&gt;&lt;SPAN&gt; = &lt;/SPAN&gt;&lt;SPAN&gt;await&lt;/SPAN&gt; &lt;SPAN&gt;fetch&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN&gt;url&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;options&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;xmlTranslate&lt;/SPAN&gt;&lt;SPAN&gt;);&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;Right now I have hardcoded like this&amp;nbsp;&lt;SPAN&gt;&lt;STRONG&gt;eval Channel ="372864u31564719" |&amp;nbsp;eval ChannelName = "4P customer", &lt;/STRONG&gt;I want to add dynamic value for diff use case in channel and channelName of search query (i.e coming from&lt;STRONG&gt; request payload)&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 11 May 2023 02:07:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-add-dynamic-value-in-search-query/m-p/642867#M222652</guid>
      <dc:creator>s0k0</dc:creator>
      <dc:date>2023-05-11T02:07:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to add dynamic value in search query?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-add-dynamic-value-in-search-query/m-p/642962#M222702</link>
      <description>&lt;P class="lia-align-left"&gt;&lt;SPAN&gt;To add dynamic values to your Splunk search query, you can use string interpolation. Here's an example of how you can modify your code to use the values from the request payload.&lt;BR /&gt;Let me know if it works.&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;method: "POST",
path: "/api/addSplunk",
handler: async (request, h) =&amp;gt; {
    const ccmData = getServerConfig(request);
    const url = ccmData["splunkApiUrl"];
    const ChannelName = request.payload.channel_name;
    const Channel = request.payload.channel_type;

    function xmlTranslate(resp) {
        return resp.text()
    }

    const httpsAgent = new https.Agent({
        rejectUnauthorized: false
    });

    // Use string interpolation to insert dynamic values in the search query
    const query = `| makeresults | eval Channel="${Channel}" | eval ChannelName="${ChannelName}" | table Channel,ChannelName | outputlookup channel.csv append=true`;

    const options = {
        method: "POST",
        headers: {
            "Authorization": "dr356654fy6",
            "Content-Type": "application/x-www-form-urlencoded"
        },
        agent: httpsAgent,
        translate: xmlTranslate,
        body: `search=${encodeURIComponent(query)}`
    };&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 11 May 2023 06:32:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-add-dynamic-value-in-search-query/m-p/642962#M222702</guid>
      <dc:creator>TrangCIC81</dc:creator>
      <dc:date>2023-05-11T06:32:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to add dynamic value in search query?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-add-dynamic-value-in-search-query/m-p/642963#M222703</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/256527"&gt;@s0k0&lt;/a&gt;&amp;nbsp;- You can use query with variables, something like this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;const ChannelName= request.payload.channel_name;
const Channel= request.payload.channel_type;
const query = `| makeresults | eval Channel="${Channel}" | eval ChannelName="${ChannelName}" | table Channel,ChannelName | outputlookup channel.csv append=true`;
const options = {
  method: "POST",
  headers: {
    "Authorization": "dr356654fy6",
    "Content-Type": "application/x-www-form-urlencoded"
  },
  agent: httpsAgent,
  translate: xmlTranslate,
  body: `search=${encodeURIComponent(query)}`
};&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kindly upvote if you find it useful!!!&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2023 06:43:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-add-dynamic-value-in-search-query/m-p/642963#M222703</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2023-05-11T06:43:49Z</dc:date>
    </item>
    <item>
      <title>Re: How to add dynamic value in search query?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-add-dynamic-value-in-search-query/m-p/642980#M222709</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/255046"&gt;@TrangCIC81&lt;/a&gt;&amp;nbsp;I tried this, didn't work.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/93915"&gt;@VatsalJagani&lt;/a&gt;&amp;nbsp;thank you so much, it works !!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2023 08:00:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-add-dynamic-value-in-search-query/m-p/642980#M222709</guid>
      <dc:creator>s0k0</dc:creator>
      <dc:date>2023-05-11T08:00:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to add dynamic value in search query?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-add-dynamic-value-in-search-query/m-p/642984#M222710</link>
      <description>&lt;P&gt;Can you verify if&amp;nbsp;the values for ChannelName and Channel do not contain any special characters that might interfere with the construction of the string in the body of the request?&lt;/P&gt;&lt;P&gt;Also try logging the values of ChannelName and Channel to the console to verify that they are being properly read.&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2023 08:04:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-add-dynamic-value-in-search-query/m-p/642984#M222710</guid>
      <dc:creator>TrangCIC81</dc:creator>
      <dc:date>2023-05-11T08:04:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to add dynamic value in search query?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-add-dynamic-value-in-search-query/m-p/642985#M222711</link>
      <description>&lt;P&gt;Yes, it doesn't have any special character, inside options object&amp;nbsp;&lt;SPAN&gt;ChannelName and Channel value&lt;/SPAN&gt;&amp;nbsp;is not getting read.&lt;/P&gt;&lt;P&gt;Outside option object it's value is getting read, I did console and check.&lt;BR /&gt;So I put whole query outside the option object then get the dynamic value and append in body&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;const&lt;/SPAN&gt; &lt;SPAN&gt;query&lt;/SPAN&gt;&lt;SPAN&gt; =&lt;/SPAN&gt;&lt;SPAN&gt; `| makeresults | eval Channel="${&lt;/SPAN&gt;&lt;SPAN&gt;Channel&lt;/SPAN&gt;&lt;SPAN&gt;}" | eval ChannelName="${&lt;/SPAN&gt;&lt;SPAN&gt;ChannelName&lt;/SPAN&gt;&lt;SPAN&gt;}" | table Channel,ChannelName | outputlookup channel.csv append=true`&lt;/SPAN&gt;&lt;SPAN&gt;;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;const&lt;/SPAN&gt; &lt;SPAN&gt;options&lt;/SPAN&gt;&lt;SPAN&gt; = {&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;method&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;"POST"&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;headers&lt;/SPAN&gt;&lt;SPAN&gt;: {&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;"Authorization"&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;authToken&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;"Content-Type"&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;"application/x-www-form-urlencoded"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;},&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;agent&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;httpsAgent&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;translate&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;xmlTranslate&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;body&lt;/SPAN&gt;&lt;SPAN&gt;:&lt;/SPAN&gt;&lt;SPAN&gt; `search=${&lt;/SPAN&gt;&lt;SPAN&gt;query&lt;/SPAN&gt;&lt;SPAN&gt;}`&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;};&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt;This works !!&lt;/DIV&gt;&lt;P&gt;&lt;BR /&gt;Thank you so much for resolving.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2023 08:11:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-add-dynamic-value-in-search-query/m-p/642985#M222711</guid>
      <dc:creator>s0k0</dc:creator>
      <dc:date>2023-05-11T08:11:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to add dynamic value in search query?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-add-dynamic-value-in-search-query/m-p/642986#M222712</link>
      <description>&lt;P&gt;Ah ok. No problem.&amp;nbsp;&lt;BR /&gt;Cheers!!&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2023 08:16:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-add-dynamic-value-in-search-query/m-p/642986#M222712</guid>
      <dc:creator>TrangCIC81</dc:creator>
      <dc:date>2023-05-11T08:16:13Z</dc:date>
    </item>
    <item>
      <title>Re: How to add dynamic value in search query?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-add-dynamic-value-in-search-query/m-p/643021#M222729</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/256527"&gt;@s0k0&lt;/a&gt;&amp;nbsp;- I'm glad that it works!! Kindly consider accepting my answer which helped you resolve your question, so that other community members can easily see it.&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2023 11:26:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-add-dynamic-value-in-search-query/m-p/643021#M222729</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2023-05-11T11:26:34Z</dc:date>
    </item>
  </channel>
</rss>

