Splunk Search

Parameters for search

klausJohan
Path Finder

Hi,

What would be the available options in order to parameterize a search in a Splunk view ?

Let's say that all events that I'm indexing into Splunk contain a field , and that field can have values from a limited set of values. How would I make it possible for the user to specify that he is interested in events with fields having a particular value.

Thanks

0 Karma

somesoni2
Revered Legend

In the splunk views, you can use any of the Splunk controls like Dropdown (if user has to select from pre-defined values) or textbox which will allow user to specify the filter criteria. After that you can change your search to take values from the control.

If you have a dropdown with name field1 [which provides value for say FIELD1] then your search wil become

index=yourindex sourcetype=yoursourcetype.... FIELD1=$field1$...

You can add many control and use them in your search.

0 Karma

klausJohan
Path Finder

Dropdown would be perfect for me, if I could dinamically define the available options when the page loads.

0 Karma

lukejadamec
Super Champion

If you are searching for a single value, the simply search for it:

field="value"

If you are searching for more then one value, the use the OR operator (must be in caps)

field="value" OR field="value"

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...