Hi,
What would be the available options in order to parameterize a search in a Splunk view ?
Let's say that all events that I'm indexing into Splunk contain a field , and that field can have values from a limited set of values. How would I make it possible for the user to specify that he is interested in events with fields having a particular value.
Thanks
In the splunk views, you can use any of the Splunk controls like Dropdown (if user has to select from pre-defined values) or textbox which will allow user to specify the filter criteria. After that you can change your search to take values from the control.
If you have a dropdown with name field1 [which provides value for say FIELD1] then your search wil become
index=yourindex sourcetype=yoursourcetype.... FIELD1=$field1$...
You can add many control and use them in your search.
Dropdown would be perfect for me, if I could dinamically define the available options when the page loads.
If you are searching for a single value, the simply search for it:
field="value"
If you are searching for more then one value, the use the OR operator (must be in caps)
field="value" OR field="value"