Splunk Search

Construct map command query in eval statement

drewg33
Engager

I am having trouble constructing a search command in an Eval statement. I stripped it down to its most basic form to troubleshoot, but I still can't get that to work.

| makeresults 
| eval test = "search earliest=1576263600 latest=1576512000 index=security sourcetype=host_info | head 10" 
| map search="$test$"

I also tried this which was recommended in a different splunk answers post, but that still didn't work for me on Splunk version 7.1.6.

| makeresults 
| eval test = "earliest=1576263600 latest=1576512000 index=security sourcetype=host_info | head 10" 
| map search="search [| makeresults | eval evaltest=$test$ | return $evaltest]"
0 Karma

Anantha123
Communicator

try giving double $ sign . passed variables should be in $$ sign.

| map search="search [| makeresults | eval evaltest="$$test$$" | return $evaltest]"

Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...