This should be trivial to do, but I am not able to search using variables.
Eks this works
some splunk data | search direction="out"
But this does not:
some splunk data | eval test="out" | search direction="$test$"
nor this:
some splunk data | eval test="out" | search direction=$test$
What do I do wrong. Search google, but did not find and working solution.
What is the requirement here? From where this variable should come from? If it's a field from same search, you can use like this
some splunk data | eval test="out" | where direction=test
What is the requirement here? From where this variable should come from? If it's a field from same search, you can use like this
some splunk data | eval test="out" | where direction=test
That did do it. Data is coming from a drop down input on a dashboard.
If you post it as an answer I can accept it 🙂