Splunk Search

Defining variables or constants

tachu
Explorer

I would like to be able to have a predefined variable or constant to run queries with by example

source="syslog" login ip!=OFFICEIPS

where OFFICEIPS is a set of ip's

that way it wont require for us to know all ips every time we do a search but just mantain a table or variable every time a new subnet is added

Tags (2)
1 Solution

sdaniels
Splunk Employee
Splunk Employee

sdaniels
Splunk Employee
Splunk Employee

tachu
Explorer

Thx will give it a shot!

0 Karma
Get Updates on the Splunk Community!

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...