#SPLUNK_ARG_0 Script name
#SPLUNK_ARG_1 Number of events returned
#SPLUNK_ARG_2 Search terms
#SPLUNK_ARG_3 Fully qualified query string
#SPLUNK_ARG_4 Name of report
#SPLUNK_ARG_5 Trigger reason (for example, "The number of events was greater than 1")
#SPLUNK_ARG_6 Browser URL to view the report
#SPLUNK_ARG_7 Not used for historical reasons
#SPLUNK_ARG_8 File in which the results for this search are stored (contains raw results)
What is the difference between 3 and 2? These seem to be the same for me all the time.
Try calling a macro
in your search. When you do, the macro
name will show up in #2 but the expanded macro
code will be placed in-line for #3. Similar things happen for saved searches
, etc. It is similar to what you see in the Job Inspector
when you examine normalized search
(which is analogous to #3) and compare it to what you had in your search bar (which is analogous to #2).