Splunk Search

Export dilldown search with variables substituted

shaquibk
Explorer

Hi Team,

I have a query related to drilldown searches of notables. I want to export/show results of drilldown searches with variables substituted corresponding to each notable.

Example, consider following search:
`notable` | search event_id="XXXXXX" | table drilldown_search,drilldown_earliest,drilldown_latest

The above search will give me drilldown search but with variables not substituted. I want the variables to be substituted in the search results.

Actual result of above search - index=abc action=failure user="$user$" 

Desired output - index=abc action=failure user="[email protected]" 

Let me know if any further info is needed. Thanks in advance.

Regards,

Shaquib

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Vibe-coding, AI, and Splunkcraft: Highlights from the .conf26 Builder Bar

If you stopped by the Builder Bar at .conf26, thank you! This year, we brought ...

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...