Splunk Search

How can I select the index to search dynamically?

sillingworth
Path Finder

I want to say

| eval my_index=(something, probably using if)
| append [index=(whatever my_index is)]

How can I do this? How can I set index= to a field, rather that just a string?

Further question: Can I make that append completely optional, so if a certain condition isn't met it won't run the subsearch at all (my workaround was going to be setting my_index to something that will never match a real index name)?

Tags (1)
0 Karma

DalJeanis
Legend

This version replaces the incoming records with the results of the search

| eval my_index=case(myfield="foo","bar",myfield="fizz","buzz",true(),"AintGotNoIndexByThisName")
| map search="search index=$my_index$ some other search terms and pipes here | table index myfield3 myfield7"

This version does a search once for each value of index and appends it to the current result set...

| eval my_index=case(myfield="foo","bar",myfield="fizz","buzz",true(),"AintGotNoIndexByThisName")
| appendpipe 
    [ | table index 
      | dedup index
      | map search="search index=$my_index$ some other search terms and pipes here | table index myfield3 myfield7"
    ]

As a general case, the only thing that I've found that allows any usage of field values to replace search terms is map. Which is slow and clumsy and should be avoided if possible.

sillingworth
Path Finder

Ah, I didn't know you could use $something$ for things other that tokens. Thanks!

Is there a reason you couldn't just do:

| eval my_index=(something, probably using if)
| append index=$my_index$ .....

? I appreciate yours makes it easy to have several indexes.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...