Splunk Search

How can I select the index to search dynamically?

sillingworth
Path Finder

I want to say

| eval my_index=(something, probably using if)
| append [index=(whatever my_index is)]

How can I do this? How can I set index= to a field, rather that just a string?

Further question: Can I make that append completely optional, so if a certain condition isn't met it won't run the subsearch at all (my workaround was going to be setting my_index to something that will never match a real index name)?

Tags (1)
0 Karma

DalJeanis
Legend

This version replaces the incoming records with the results of the search

| eval my_index=case(myfield="foo","bar",myfield="fizz","buzz",true(),"AintGotNoIndexByThisName")
| map search="search index=$my_index$ some other search terms and pipes here | table index myfield3 myfield7"

This version does a search once for each value of index and appends it to the current result set...

| eval my_index=case(myfield="foo","bar",myfield="fizz","buzz",true(),"AintGotNoIndexByThisName")
| appendpipe 
    [ | table index 
      | dedup index
      | map search="search index=$my_index$ some other search terms and pipes here | table index myfield3 myfield7"
    ]

As a general case, the only thing that I've found that allows any usage of field values to replace search terms is map. Which is slow and clumsy and should be avoided if possible.

sillingworth
Path Finder

Ah, I didn't know you could use $something$ for things other that tokens. Thanks!

Is there a reason you couldn't just do:

| eval my_index=(something, probably using if)
| append index=$my_index$ .....

? I appreciate yours makes it easy to have several indexes.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...