Security

allow user to run search contained in lookup

dmcintosh1972
Explorer

I have created a lookup. fairly basic 2 columns, column 1 has an ID the second a search string.

ID searchstring
1 source =xyz

My users get the ID from a separate system and rather than remember the search string or lookup the string themselves they would like to run the search through itself using the search id.

e.g. | inputlookup table where ID=1 | fields searchstring | run searchstring as a splunksearch

Is this possible?

Thanks

Tags (1)
0 Karma

jawaharas
Motivator

For your requirement, you can try using 'macros'.

You can find macro option by navigation through - Settings->Advanced search->Search macros

Reference:
https://docs.splunk.com/Documentation/Splunk/7.3.0/Knowledge/Definesearchmacros
https://docs.splunk.com/Documentation/Splunk/7.3.0/Knowledge/Searchmacroexamples

0 Karma

jawaharas
Motivator

@dmcintosh1972
Can you accept the answer if it's helped you? Thanks.

0 Karma

jaime_ramirez
Communicator

Maybe with the map command. I will try making an example and check if its possible.

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...