Splunk Search

Parameters for search

klausJohan
Path Finder

Hi,

What would be the available options in order to parameterize a search in a Splunk view ?

Let's say that all events that I'm indexing into Splunk contain a field , and that field can have values from a limited set of values. How would I make it possible for the user to specify that he is interested in events with fields having a particular value.

Thanks

0 Karma

somesoni2
Revered Legend

In the splunk views, you can use any of the Splunk controls like Dropdown (if user has to select from pre-defined values) or textbox which will allow user to specify the filter criteria. After that you can change your search to take values from the control.

If you have a dropdown with name field1 [which provides value for say FIELD1] then your search wil become

index=yourindex sourcetype=yoursourcetype.... FIELD1=$field1$...

You can add many control and use them in your search.

0 Karma

klausJohan
Path Finder

Dropdown would be perfect for me, if I could dinamically define the available options when the page loads.

0 Karma

lukejadamec
Super Champion

If you are searching for a single value, the simply search for it:

field="value"

If you are searching for more then one value, the use the OR operator (must be in caps)

field="value" OR field="value"

0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...