Well, that is unfortunate, since the variable part would solve this issue. We have x-customers, y-applications per customer & 3-6 environments per customer. Indexes share the same naming convention: index=<$customer>-<$app01>-<$environment> We have 10+ applications, 3-6 environments per customer & every search is a hard-coded index with customer-app-evironment. We have a dashboard per customer created with specific searches but for ad-hoc debugging this is my personal go-to (splunk search) for filtering interesting data. The reason for this post was to create an "ultimate one-line" search, where only 2 parts of the data would change (input for the search => variable). I am not sure this is the right approach, but it definitely looks like the easiest.
... View more