Splunk Search

How to pass multiple searches from a form?

a212830
Champion

Hi,

I have a search that crosses multiple indexes and sourcetypes, and the customer wants the ability to choose these searches (all or multiple) and have them run. I have macros set up for the searches, and it looks like Multi-select is the option to use in the form, but I can't figure out how to pass these as parameters in the search. Can someone help me out?

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

If your searches append to each other as plain text you could store those searches in the value of your input, and use the input's token as the sole search.

That's usually not the case though, most combination searches are more complicated than that. In such a case you can use placeholder values in your input, and set the actual search token using a conditional set element in simple XML: http://docs.splunk.com/Documentation/Splunk/6.3.3/Viz/PanelreferenceforSimplifiedXML#Eval.2C_Link.2C...

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...