Rather simple question but not sure if there is a solution for this.
I am running a search
search event_number=123
This search is powering multiple reports. Each report, right now, has that value embedded. Twice a month event_number
changes and increases by 1. So when we prepare for the next event, we have to go through all reports and change search strings to
search event_number=124
Was wondering if there is a simple way to set up the variable/constant X=123
and run search
search event_number=X
So when we do change to event_number 125
, we would have to do it only once.
Thanks!
You're looking for macros: http://docs.splunk.com/Documentation/Splunk/6.1.2/Search/Usesearchmacros
Or eventtypes. Take your pick. 🙂