Form searches are saved searches that appear as forms when run. Save any search with parameters to be specified by the user running the search. The user fills in the parameters before running the search. You can create a sophisticated saved search and save it as a form with as many form fields as you like.
For example, you can define a search that returns all Web server errors for any username to be specified at search time:
When run, this search appears as a form labeled user.

The search 503 OR 500 OR 404 sourcetype=access_common is still part of the search, but does not appear to the user.
Note: Form search works via text substitution, so the form fields can consist of anything, not just an indexed or an extracted field.
Create a form searchCreate a form search the same way you create a saved search, with these additional steps:
For example, the search
will appear as the following:

Create form searches for indexed and extracted fields.
Preface your form field with the field name and surround the form field with quotes.
For example:
Save this search as Daily indexing volume, and a user running the search sees:

You can also specify form searches that have a list of valid values. The form generated will show a drop-down list. For example, the search
sourcetype=_trade_entry AND TradeID="$Trade ID$" AND TradeType $TradeType=Accepted,Rejected,Hold$
This search limits TradeType to three values and presents them in a drop-down:

Valid values can also come from an external source. For example:
$user={/static/html/imap.users}$ ['value1','value2','value3','value4']
Share your form searchOnce you have refined your search, you can distribute it to your users.
Save it
Comments
No comments have been submitted.