Splunk Search

Reference multiple fields into a single name

irkey
Explorer

Is there a way to reference or combine multiple fields into a single name so that it can be referenced by that new name?

For example:   somefield IN (a,b,c,d)

If I  run  a query for "somefield" I get "a", "b", "c", "d" returned.

I want to be able to refer to "somefield" by a single name.  Is that possible?

So if run a query for "somefield", I would get the aggregate results of a,b,c,d ?

Labels (2)

gcusello
SplunkTrust
SplunkTrust

Hi @irkey ,

you have two choices:

use a macro, as hinted by @KendallW ,

use an eventtype containing the search parameters, for more infos see at https://docs.splunk.com/Documentation/Splunk/9.3.0/Knowledge/Abouteventtypes

in this way if you created an evenntype called e.g. "somefield" containing  somefield IN (a,b,c,d), you can call it using 

eventtype=somefield

Ciao.

Giuseppe

0 Karma

irkey
Explorer

Thank you, I will investigate this as well to see what works best.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @irkey ,

let us know if we can help you more, or, please, accept one answer for the other people of Community.

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated by all the contributors 😉

0 Karma

KendallW
Contributor
0 Karma

irkey
Explorer

Thank you, I will investigate this.

0 Karma
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...