Alerting

how to use saved search in the middle of query

abhishekdubey00
Engager

alt text

see the below image , how to save the highlighted section of the search in a saved search.. So that I can reuse that

Tags (1)
0 Karma

whrg
Motivator

I can see a lot of field extractions and evals in the highlighted section.
I think it might be best if you create field extractions and calculated fields via Settings / Fields. Then the fields will be automatically created for every search.

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@abhishekdubey006

if you want to reuse search portions in mutliple searches then use macros.

http://docs.splunk.com/Documentation/Splunk/7.2.1/admin/macrosconf

abhishekdubey00
Engager

I don't have access of admin user so how to use through UI

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust
0 Karma

abhishekdubey00
Engager

macro will not work in the middle of the query

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...