Hi. I am going to set up the same search - for a lot of different hosts.(20)
The result of the search is displayed on 2 different dashboards.
The search is running every 30 minutes - thus updating the dashboard every 30 minutes.
I would like to use the same search - and just reference the different hosts - instead of having 20 saved searches which are the same - only difference is the host name.
How do I accomplish this?
This sounds like a good situation to use a search macro. I could describe it a bit more but really I think the docs explain the concept best though: http://docs.splunk.com/Documentation/Splunk/latest/User/CreateAndUseSearchMacros
No problem! Could you please mark my answer as accepted? Thanks!
Great! thank you so much!