Splunk Search

I have to filter my results based on a static list of known services. How can I avoid having to append this long filter to each my searches?

tragiccode
New Member

i constantly have to filter my search results based on a static list of known Windows service names. my searches usually end up looking like so

index="wineventlog" "Ordering" OR "Pricing" OR "Catalog" ....

What capability can i look up in Splunk to avoid having to append this long filter to every search that needs to only show events related to this static list of Windows services?

0 Karma
1 Solution

dkeck
Influencer

Please accept the answer, if it helped you.

Thank you

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...