Splunk Search

How do I pass an input parameter to the search string of another input?

srizan
Path Finder

I have multiple inputs in the dashboard. The first input is for various environments (hard coded). And the second input is for various accounts from the selected environment (leverages search string). I have the first input tokenized as "env" however, passing it in the second input search string as environment=$env$ doesn't yield the value from the first input.

Tags (2)
0 Karma

srizan
Path Finder

Yeah! Seems like there was some issue with caching maybe, it worked in incognito.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @srizan,
searches are the same in inputs and panels, so you can manage tokens in the same way.
check if you need quotes because $env$ could contain spaces:

environment="$env$"

Ciao.
Giuseppe

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @srizan,
what do you mean with " it worked in incognito."?
Did you solved?

Ciao.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

From Alert to Resolution: How Splunk Observability Helps SREs Navigate Critical ...

It's 3:17 AM, and your phone buzzes with an urgent alert. Wire transfer processing times have spiked, and ...

ATTENTION!! We’re MOVING (not really)

Hey, all! In an effort to keep this Slack workspace secure and also to make our new members' experience easy, ...

Splunk Admins: Build a Smarter Stack with These Must-See .conf25 Sessions

  Whether you're running a complex Splunk deployment or just getting your bearings as a new admin, .conf25 ...