Is there a way to parameterize a search, for instance, lollipop="{first, second, third}"
.
I want to retrieve a table of data based on multiple search instances where the parameter changes based on a comma-delimited value.
You can use a macro
or you can also use the savedsearch
command, which is probably what you are seeking (search for replace_me
😞
https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Savedsearch
Have you tried using Splunk Macros:
https://docs.splunk.com/Documentation/Splunk/7.3.0/Knowledge/Searchmacroexamples
Cheers!!!