Splunk Search

Retrieve the name of the current search

Scott_Kudelski
Explorer

I would like to be able to retrieve the name of the current search to pass to a macro in the search.

Saved Search name in app "Access - Cleartext Password At Rest"

| from datamodel:"Compute_Inventory"."Cleartext_Passwords"
| `get_info($SEARCH_NAME$)`
| stats max(_time) as "lastTime",latest(_raw) as "orig_raw",values(tag) as "tag",count by "dest","user","password"

Macro "get_info"
Argument: searchname
lookup searchparms $searchname$

So in this example when the scheduled search "Access - Cleartext Password At Rest" is run, it would lookup information from "searchparms" for "Access - Cleartext Password At Rest"

Labels (2)
0 Karma

bowesmana
SplunkTrust
SplunkTrust
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Try $job.label$

---
If this reply helps you, Karma would be appreciated.
0 Karma

Scott_Kudelski
Explorer

@richgalloway I was unable to get any results for $job.label$

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...