Splunk Search

Retrieve the name of the current search

Scott_Kudelski
Explorer

I would like to be able to retrieve the name of the current search to pass to a macro in the search.

Saved Search name in app "Access - Cleartext Password At Rest"

| from datamodel:"Compute_Inventory"."Cleartext_Passwords"
| `get_info($SEARCH_NAME$)`
| stats max(_time) as "lastTime",latest(_raw) as "orig_raw",values(tag) as "tag",count by "dest","user","password"

Macro "get_info"
Argument: searchname
lookup searchparms $searchname$

So in this example when the scheduled search "Access - Cleartext Password At Rest" is run, it would lookup information from "searchparms" for "Access - Cleartext Password At Rest"

Labels (3)
0 Karma

bowesmana
SplunkTrust
SplunkTrust
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Try $job.label$

---
If this reply helps you, Karma would be appreciated.
0 Karma

Scott_Kudelski
Explorer

@richgalloway I was unable to get any results for $job.label$

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...