Splunk Search

Defining variables or constants

tachu
Explorer

I would like to be able to have a predefined variable or constant to run queries with by example

source="syslog" login ip!=OFFICEIPS

where OFFICEIPS is a set of ip's

that way it wont require for us to know all ips every time we do a search but just mantain a table or variable every time a new subnet is added

Tags (2)
1 Solution

sdaniels
Splunk Employee
Splunk Employee

sdaniels
Splunk Employee
Splunk Employee

tachu
Explorer

Thx will give it a shot!

0 Karma
Get Updates on the Splunk Community!

Community Content Calendar, November Edition

Welcome to the November edition of our Community Spotlight! Each month, we dive into the Splunk Community to ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...