Hi
we have a microservices based system and have several services running , the developers put unti a lookup table the complete search string, . I am ablr to retrieve the string from lookup but not able to execute it
| inputlookup searchstring.csv | streamstats count as Rowcount | where Rowcount =1 | search Search_String
a sample of what is there in Search_String , this one is simple but sometimes there are complex queries
index=abc* AND source= xyz* AND host=* AND ERROR=50* | stats count as 5xx_Errors
how to make the Search string in lookup execute
I don't think you can do that. Even fiddling with the format command best you can do is your own formatted parameters for the search command. I don't see any way to run the subsearch output as a whole command to be parsed and executed by splunk.
If you need them to be able to use searches on their own from external software, let them use API.