I remember being able to include a standard text file, perhaps a .csv, in the 3.x branch. The search would then iterate line-by-line through the entries in said file, much like a subsearch would work. While I suspect I could do this with a python script of some kind, is there any way to do this in 4.x? The use case scenario in this case could be iterating through a very long list of domain names.
Thanks!
It looks like this answer works out a bit better:
http://answers.splunk.com/questions/4044/how-can-i-set-up-a-watchlist
There are a few ways you can input files as search terms.
inputcsv and inputlookup
http://www.splunk.com/base/Documentation/latest/SearchReference/Inputcsv http://www.splunk.com/base/Documentation/latest/SearchReference/Inputlookup
Both of the above commands should allow you to input a csv or similar data.
The Inputcsv bit doesn't quite do what I was looking for, unless I am confused about its operation.