Splunk dashboard studio12/23/2023 ![]() You cannot specify any properties such as queryParameters, refresh, and refreshType for chain searches. Any token you create can be used in a search of type ds.chain, but time-related tokens can only be used in the base search. You can use tokens in both base and chain searches. This functionality is similar to the way that you might have used post-process searches using Simple XML. You can extend many independent chain searches from the base search, and you can extend many second level chains that use the first level chain as their primary data source, but you cannot have a third level of chains that use the a second level chain as a primary data source. Search 3 is now the following: base search + Chain search 2 + Chain search 2b Search 2 is now the following: base search + Chain search 2 + Chain search 2a Search 1 is now the following: base search + Chain search 1 There are many different combinations you can use once you've established the base search, for example: To extend a chain search, choose the first chain search as the parent search instead of selecting your base search. You can use this method to create as many chain searches off of the base search as you want, but you can only create one additional chain search by extending an existing chain search.
0 Comments
Leave a Reply.AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |