Hi all, I have just downloaded the app "SSL Certificate lookup" from splunk base and it's working fine. with following query:
| makeresults | eval dest="myhost1, myhost2", dest = split(dest,",") | lookup sslcert_lookup dest | eval dayleft=round(ssl_validity_window/86400) | table dest,dayleft, ssl_is_valid,ssl_issuer_common_name,ssl_self_issued,ssl_self_signed,ssl_version However, myhost1, myhost2 is hardcoded in the initial query and I would like to dynamically pass as parameters all host matching a specific query: index=* host=*myserver* I tried several things without success (subsearch, saved search, macro...), any idea how I could achieve that ? Any help would be greatly appreciated !
... View more