Splunk Search

How to pass multiple searches from a form?

a212830
Champion

Hi,

I have a search that crosses multiple indexes and sourcetypes, and the customer wants the ability to choose these searches (all or multiple) and have them run. I have macros set up for the searches, and it looks like Multi-select is the option to use in the form, but I can't figure out how to pass these as parameters in the search. Can someone help me out?

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

If your searches append to each other as plain text you could store those searches in the value of your input, and use the input's token as the sole search.

That's usually not the case though, most combination searches are more complicated than that. In such a case you can use placeholder values in your input, and set the actual search token using a conditional set element in simple XML: http://docs.splunk.com/Documentation/Splunk/6.3.3/Viz/PanelreferenceforSimplifiedXML#Eval.2C_Link.2C...

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...