Splunk Search

How to pass multiple searches from a form?

a212830
Champion

Hi,

I have a search that crosses multiple indexes and sourcetypes, and the customer wants the ability to choose these searches (all or multiple) and have them run. I have macros set up for the searches, and it looks like Multi-select is the option to use in the form, but I can't figure out how to pass these as parameters in the search. Can someone help me out?

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

If your searches append to each other as plain text you could store those searches in the value of your input, and use the input's token as the sole search.

That's usually not the case though, most combination searches are more complicated than that. In such a case you can use placeholder values in your input, and set the actual search token using a conditional set element in simple XML: http://docs.splunk.com/Documentation/Splunk/6.3.3/Viz/PanelreferenceforSimplifiedXML#Eval.2C_Link.2C...

0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...