Splunk Enterprise Security

What do backticks do in searches?

hcheang
Path Finder

Hello,

I was trying to understand the queries used for ES app and found that many searches are simplified as whatevers inside single quotation marks (').

Is this alternative way of using |savedsearch ? Or is it only used for ES?

1 Solution

Raghav2384
Motivator

You mean something like this "pageviews_per_second". I have never used ES app but anything in single quotes means a macro.

Go to Settings>Advanced Search>Search Macros> you should see the Name of the macro and search associated with it in the Definition field and the App macro resides/used in.

Thanks,
Raghav

View solution in original post

Raghav2384
Motivator

You mean something like this "pageviews_per_second". I have never used ES app but anything in single quotes means a macro.

Go to Settings>Advanced Search>Search Macros> you should see the Name of the macro and search associated with it in the Definition field and the App macro resides/used in.

Thanks,
Raghav

joe_kraxner
Explorer

I believe those are ticks (`) not single quotes (').

hcheang
Path Finder

oh I see. Thanks!

0 Karma

joe_kraxner
Explorer

I believe those are ticks (`) not single quotes (').

0 Karma
Get Updates on the Splunk Community!

Detecting Brute Force Account Takeover Fraud with Splunk

This article is the second in a three-part series exploring advanced fraud detection techniques using Splunk. ...

Buttercup Games: Further Dashboarding Techniques (Part 9)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Buttercup Games: Further Dashboarding Techniques (Part 8)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...