Dashboards & Visualizations

Splunk and variables/constants

ateterine
Path Finder

Rather simple question but not sure if there is a solution for this.

I am running a search

search event_number=123

This search is powering multiple reports. Each report, right now, has that value embedded. Twice a month event_number changes and increases by 1. So when we prepare for the next event, we have to go through all reports and change search strings to

search event_number=124

Was wondering if there is a simple way to set up the variable/constant X=123 and run search
search event_number=X
So when we do change to event_number 125, we would have to do it only once.

Thanks!

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Ayn
Legend

Or eventtypes. Take your pick. 🙂

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...