Splunk Enterprise Security

What do backticks do in searches?

Path Finder

Hello,

I was trying to understand the queries used for ES app and found that many searches are simplified as whatevers inside single quotation marks (').

Is this alternative way of using |savedsearch ? Or is it only used for ES?

1 Solution

Motivator

You mean something like this "pageviews_per_second". I have never used ES app but anything in single quotes means a macro.

Go to Settings>Advanced Search>Search Macros> you should see the Name of the macro and search associated with it in the Definition field and the App macro resides/used in.

Thanks,
Raghav

View solution in original post

Motivator

You mean something like this "pageviews_per_second". I have never used ES app but anything in single quotes means a macro.

Go to Settings>Advanced Search>Search Macros> you should see the Name of the macro and search associated with it in the Definition field and the App macro resides/used in.

Thanks,
Raghav

View solution in original post

Explorer

I believe those are ticks (`) not single quotes (').

Path Finder

oh I see. Thanks!

0 Karma

Explorer

I believe those are ticks (`) not single quotes (').

0 Karma