Splunk Search

How to print a splunk variable?

satyajit7
Explorer

How to print a splunk default variable in search query? Actually I have two variables like $job.earliestTime$ and $job.latestTime$. And I want this two to use in alert so that it will give me the date range in the pdf. Can somebody please suggest. 

 

 

Labels (3)
0 Karma
1 Solution

satyajit7
Explorer

@gcusello Thanks for your reply and I got solution as well.  I have looked to that doc and got some ideas. Now I'm able to print the date range in Tabular format.

My code looks like this and it's working perfectly

....|addinfo| eval startDate= strftime(info_min_time,"%Y-%m-%d")| eval endDate= strftime(info_max_time,"%Y-%m-%d")|table startDate endDate.

Thanks again.

View solution in original post

0 Karma

satyajit7
Explorer

And I'm trying to use like this 

.....|eval startDate = $job.earliestTime$ | eval endDate = $job.latestTime$ | table startDate endDate 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @satyajit7,

see the addinfo command (https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Addinfo)

you need info_min_time and info_max_time.

ciao.

Giuseppe

0 Karma

satyajit7
Explorer

@gcusello Thanks for your reply and I got solution as well.  I have looked to that doc and got some ideas. Now I'm able to print the date range in Tabular format.

My code looks like this and it's working perfectly

....|addinfo| eval startDate= strftime(info_min_time,"%Y-%m-%d")| eval endDate= strftime(info_max_time,"%Y-%m-%d")|table startDate endDate.

Thanks again.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @satyajit7,

good for your and see next time!

Ciao and happy splunking.

Giuseppe

P.S.: Karma Points are appreciated 😉

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Value Insights: Now Generally Available in the CMC

Organizations are under pressure to move faster, control cost, expand AI adoption, and prove value with more ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

Another quarter, another wave of innovation. From complex integrations to pushing the limits ...