Splunk Search

I have to filter my results based on a static list of known services. How can I avoid having to append this long filter to each my searches?

New Member

i constantly have to filter my search results based on a static list of known Windows service names. my searches usually end up looking like so

index="wineventlog" "Ordering" OR "Pricing" OR "Catalog" ....

What capability can i look up in Splunk to avoid having to append this long filter to every search that needs to only show events related to this static list of Windows services?

0 Karma
1 Solution

Influencer

Please accept the answer, if it helped you.

Thank you

0 Karma
Don’t Miss Global Splunk
User Groups Week!

Free LIVE events worldwide 2/8-2/12
Connect, learn, and collect rad prizes and swag!