Splunk Search

How to parameterize a search?

foxjazz
New Member

Is there a way to parameterize a search, for instance, lollipop="{first, second, third}".
I want to retrieve a table of data based on multiple search instances where the parameter changes based on a comma-delimited value.

0 Karma

woodcock
Esteemed Legend

You can use a macro or you can also use the savedsearch command, which is probably what you are seeking (search for replace_me😞
https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Savedsearch

0 Karma

jaime_ramirez
Communicator
0 Karma
Get Updates on the Splunk Community!

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...

What’s New in Splunk Observability Cloud: January Feature Highlights & Deep Dives

Splunk Observability Cloud continues to evolve, empowering engineering and operations teams with advanced ...