Splunk Search

Does splunk support parameterized queries

gregbujak
Path Finder

I am curious if parametrized queries are possible within within splunk dashboards or searches:

ex. query: foo=bar AND env=${VARIABLE}

I would then like to be able to define VARIABLE at a higher level or perhaps even have a preamble in the query such as: SET VARIABLE=prod : foo=bar AND env=${VARIABLE}.

This appears to be a similar question: link text

Thanks

Tags (1)

bbingham
Builder

Use the form dashboard or the pulldown dashboard, here would be an example:

<form class="formsearch">
       <label>Test Form</label>
       <fieldset>
              <input type="dropdown" token="breakdown" searchWhenChanged="true">
                       <label>Breakdown</label>
                       <choice value="QHour">Quarter Hour</choice>
                       <choice value="Hour">Hour</choice>
              </input>
       </fieldset>

       <row>
              <chart>
                     <searchString>index=main $breakdown$ </searchString>
                     <title>Blah</title>
              </chart>
       </row>
  </form>

So the FieldSet block builds a drop down menu and sets the variable "breakdown" to what ever the user selects, then passes that variable to a chart.

Hope this helps!

gregbujak
Path Finder

Thanks, that looks like a good place to start.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Data Management Digest – September 2026

    Welcome to the September 2026 edition of Data Management Digest! September brought a fresh wave of ...

Federated Search for CloudWatch Unified Data Store Is Generally Available

As organizations modernize their cloud environments, AWS workloads generate more security, operational, and ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...