Splunk Search

Export dilldown search with variables substituted

shaquibk
Explorer

Hi Team,

I have a query related to drilldown searches of notables. I want to export/show results of drilldown searches with variables substituted corresponding to each notable.

Example, consider following search:
`notable` | search event_id="XXXXXX" | table drilldown_search,drilldown_earliest,drilldown_latest

The above search will give me drilldown search but with variables not substituted. I want the variables to be substituted in the search results.

Actual result of above search - index=abc action=failure user="$user$" 

Desired output - index=abc action=failure user="johndoe@example.com" 

Let me know if any further info is needed. Thanks in advance.

Regards,

Shaquib

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...