The closest question I came to is this one, but it's not quite there (and it's old). I have a saved search - actually an alert, with actions - that I want to pass dynamic SPL into. You can do this with dashboards and tokens, of course, but I'm specifically looking for an alert that I'm executing over the API. So I may request something like this over the API: https://splunk.mycompany.com:8089/en-US/app/myApp/search?s=%2FservicesNS%2Fnobody%2FmyApp%2Fsaved%2Fsearches%2FmySearch&ExecID=12345 Where the saved search has something like "Execution_ID=$ExecID$" in it - just like you would when requesting a dashboard. The value for $ExecID$ is unique and populating a lookup table for this simple need seems like serious overkill - and it probab;y doesn't even accomplish what I need. I hope this is written clearly enough. I'm 99% sure it can't be done, but it's been a few years since that last question, and, as noted, it's not really a match, anyway. Thanks.
... View more