Dashboards & Visualizations

Splunk and variables/constants

ateterine
Path Finder

Rather simple question but not sure if there is a solution for this.

I am running a search

search event_number=123

This search is powering multiple reports. Each report, right now, has that value embedded. Twice a month event_number changes and increases by 1. So when we prepare for the next event, we have to go through all reports and change search strings to

search event_number=124

Was wondering if there is a simple way to set up the variable/constant X=123 and run search
search event_number=X
So when we do change to event_number 125, we would have to do it only once.

Thanks!

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Ayn
Legend

Or eventtypes. Take your pick. 🙂

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...