Splunk Search

How to parameterize a search?

foxjazz
New Member

Is there a way to parameterize a search, for instance, lollipop="{first, second, third}".
I want to retrieve a table of data based on multiple search instances where the parameter changes based on a comma-delimited value.

0 Karma

woodcock
Esteemed Legend

You can use a macro or you can also use the savedsearch command, which is probably what you are seeking (search for replace_me😞
https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Savedsearch

0 Karma

jaime_ramirez
Communicator
0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...