Splunk Search

How to print a splunk variable?

satyajit7
Explorer

How to print a splunk default variable in search query? Actually I have two variables like $job.earliestTime$ and $job.latestTime$. And I want this two to use in alert so that it will give me the date range in the pdf. Can somebody please suggest. 

 

 

Labels (3)
0 Karma
1 Solution

satyajit7
Explorer

@gcusello Thanks for your reply and I got solution as well.  I have looked to that doc and got some ideas. Now I'm able to print the date range in Tabular format.

My code looks like this and it's working perfectly

....|addinfo| eval startDate= strftime(info_min_time,"%Y-%m-%d")| eval endDate= strftime(info_max_time,"%Y-%m-%d")|table startDate endDate.

Thanks again.

View solution in original post

0 Karma

satyajit7
Explorer

And I'm trying to use like this 

.....|eval startDate = $job.earliestTime$ | eval endDate = $job.latestTime$ | table startDate endDate 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @satyajit7,

see the addinfo command (https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Addinfo)

you need info_min_time and info_max_time.

ciao.

Giuseppe

0 Karma

satyajit7
Explorer

@gcusello Thanks for your reply and I got solution as well.  I have looked to that doc and got some ideas. Now I'm able to print the date range in Tabular format.

My code looks like this and it's working perfectly

....|addinfo| eval startDate= strftime(info_min_time,"%Y-%m-%d")| eval endDate= strftime(info_max_time,"%Y-%m-%d")|table startDate endDate.

Thanks again.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @satyajit7,

good for your and see next time!

Ciao and happy splunking.

Giuseppe

P.S.: Karma Points are appreciated 😉

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...