I have created a lookup. fairly basic 2 columns, column 1 has an ID the second a search string.
ID searchstring
1 source =xyz
My users get the ID from a separate system and rather than remember the search string or lookup the string themselves they would like to run the search through itself using the search id.
e.g. | inputlookup table where ID=1 | fields searchstring | run searchstring as a splunksearch
Is this possible?
Thanks
For your requirement, you can try using 'macros'.
You can find macro option by navigation through - Settings->Advanced search->Search macros
Reference:
https://docs.splunk.com/Documentation/Splunk/7.3.0/Knowledge/Definesearchmacros
https://docs.splunk.com/Documentation/Splunk/7.3.0/Knowledge/Searchmacroexamples
@dmcintosh1972
Can you accept the answer if it's helped you? Thanks.
Maybe with the map command. I will try making an example and check if its possible.