Splunk Search

Using Tokens in a Search - No Dashboard

genesiusj
Builder

Hello,
I will continue to search Answers for an answer.
Here's my issue.

I have a dashboard with numerous searches and sub-searches, as well as several tokens. I want to test each of the searches and sub-searches in the search * reporting app. What is the SPL to assign static values to these tokens so that I do not have to re-edit my SPL test these searches?

index="oit_linuxevents" AND source="ps" 
AND earliest=$Selected_Time_Range.earliest$
AND latest=$Selected_Time_Range.latest$
AND host=$hostName_tok$
AND (USER=$userId_tok$ 
   OR (USER="root" AND "*$userId_tok$*"))

Rather than having to replace all the tokens with static values, I'm looking for commands to assign those values. Then I can reuse for them for each search and sub-search.

For example, something like

after my above SPL...
| eval $hostName_tok$ = "server1"
| eval $userId_tok$="user1"
etc....

Thanks is advance for your help.
God bless,
Genesius

0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi genesiusj,
no it isn't possible bacause the format $token$ can be used only in dashboards.

But if you have a dashboard where you defined tokens' values, when you click on th "open in search" button (on the left botto side of the panel), you have the Search dashboad with the tokens' values you choose , so you haven't the problem to assign values to tokens and you can debug your search, obviously if you want to change a token's value you must manually do it.

Bye.
Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi genesiusj,
no it isn't possible bacause the format $token$ can be used only in dashboards.

But if you have a dashboard where you defined tokens' values, when you click on th "open in search" button (on the left botto side of the panel), you have the Search dashboad with the tokens' values you choose , so you haven't the problem to assign values to tokens and you can debug your search, obviously if you want to change a token's value you must manually do it.

Bye.
Giuseppe

0 Karma

genesiusj
Builder

@gcusello ,
I completely forgot about that. DOH!
Thank you so much for jogging my brain.
God bless,
Genesius

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...