Splunk Search

Can I edit my search or a filter field to search for multiple UserIDs as an input on my dashboard?

hypePG
Path Finder

Hello,

In one of my dashboards, I am using a filter field to search for one UserID. Can I edit my search or my filterfield, so it is possible to search for more than one userid as an input? e.g. like "userid1|userid2|userid3" as an input would resolve in something like "userid=userid1 OR userid=userid2 OR ..."

thanks in advance.

hype

0 Karma
1 Solution

somesoni2
Revered Legend

You can use subsearches for the same. See the example below

index=_internal  [| gentimes start=-1 | eval sourcetype="Your|Sourcetype|List|Goes|Here" | table sourcetype | makemv sourcetype delim="|" | mvexpand sourcetype ] | stats count by sourcetype

View solution in original post

somesoni2
Revered Legend

You can use subsearches for the same. See the example below

index=_internal  [| gentimes start=-1 | eval sourcetype="Your|Sourcetype|List|Goes|Here" | table sourcetype | makemv sourcetype delim="|" | mvexpand sourcetype ] | stats count by sourcetype
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...