Splunk Search

How to add to search based on the token being set

amdosh
Explorer

I want to add a few rex statements to my existing search based on the token being set. Please see example below. 

ex:
| regex _raw="$token1$"
if($token2$){
| regex _raw!="abc"
| regex _raw!="xyz"
}

Please let me know if I can achieve this in some other way. Thanks!

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...