Splunk Search

How to add a query parameter conditionally?

mamerige
Engager

I'd like to conditionally add a parameter to my Splunk query based on the version number of my application.

I have an "uploadType" input that I want to use, but only for events where the app version is over a certain number because the old versions do not contains this field.

Something like:

if appVersion >= 10.0
then include uploadType=$uploadType$,
otherwise don't filter this field.

Is this possible?

0 Karma

somesoni2
Revered Legend

Assuming you want to include the filters base search of your panels, you could do something like this

your base search (appVersion>=10.0 AND uploadType=$uploadType$) OR (appVersion<10.0) | rest of your search
0 Karma
Get Updates on the Splunk Community!

The Payment Operations Wake-Up Call: Why Financial Institutions Can't Afford ...

The same scenario plays out across financial institutions daily. A payment system fails at 11:30 AM on a busy ...

Make Your Case: A Ready-to-Send Letter for Getting Approval to Attend .conf25

Hello Splunkers, Want to attend .conf25 in Boston this year but not sure how to convince your manager? We've ...

Community Spotlight: A Splunk Expert's Journey

In the world of data analytics, some journeys leave a lasting impact not only on the individual but on the ...