Alerting

how to use saved search in the middle of query

abhishekdubey00
Engager

alt text

see the below image , how to save the highlighted section of the search in a saved search.. So that I can reuse that

Tags (1)
0 Karma

whrg
Motivator

I can see a lot of field extractions and evals in the highlighted section.
I think it might be best if you create field extractions and calculated fields via Settings / Fields. Then the fields will be automatically created for every search.

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@abhishekdubey006

if you want to reuse search portions in mutliple searches then use macros.

http://docs.splunk.com/Documentation/Splunk/7.2.1/admin/macrosconf

abhishekdubey00
Engager

I don't have access of admin user so how to use through UI

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust
0 Karma

abhishekdubey00
Engager

macro will not work in the middle of the query

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...