<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to execute macro search with REST API in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-execute-macro-search-with-REST-API/m-p/524630#M147973</link>
    <description>&lt;P&gt;It looks like the macro is trying to execute, but the content requires permissions you don't have.&amp;nbsp; What are the search and macro trying to do?&lt;/P&gt;</description>
    <pubDate>Wed, 14 Oct 2020 13:39:34 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2020-10-14T13:39:34Z</dc:date>
    <item>
      <title>How to execute macro search with REST API</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-execute-macro-search-with-REST-API/m-p/524324#M147912</link>
      <description>&lt;P&gt;How do i execute macros in rest API , example :&lt;BR /&gt;&lt;BR /&gt;curl -ku user:pass https://&amp;lt;url&amp;gt; -d search="`macro name` | table data1 data2"&lt;/P&gt;</description>
      <pubDate>Tue, 13 Oct 2020 05:47:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-execute-macro-search-with-REST-API/m-p/524324#M147912</guid>
      <dc:creator>pravinvram</dc:creator>
      <dc:date>2020-10-13T05:47:27Z</dc:date>
    </item>
    <item>
      <title>Re: How to execute macro search with REST API</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-execute-macro-search-with-REST-API/m-p/524448#M147937</link>
      <description>&lt;P&gt;Escape the backticks.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;curl -ku user:pass https://&amp;lt;url&amp;gt; -d search="\`macro name\` | table data1 data2"&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 13 Oct 2020 15:24:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-execute-macro-search-with-REST-API/m-p/524448#M147937</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-10-13T15:24:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to execute macro search with REST API</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-execute-macro-search-with-REST-API/m-p/524542#M147957</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp; - thanks for the details , tired that as well however receiving below error.&lt;/P&gt;&lt;P&gt;I own the macro and there is full permission read , still getting this error&lt;/P&gt;&lt;P&gt;&amp;lt;?xml version="1.0" encoding="UTF-8"?&amp;gt;&lt;BR /&gt;&amp;lt;response&amp;gt;&lt;BR /&gt;&amp;lt;messages&amp;gt;&lt;BR /&gt;&amp;lt;msg type="FATAL"&amp;gt;User&amp;nbsp; could not act as: admin&amp;lt;/msg&amp;gt;&lt;BR /&gt;&amp;lt;/messages&amp;gt;&lt;BR /&gt;&amp;lt;/response&amp;gt;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Oct 2020 07:17:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-execute-macro-search-with-REST-API/m-p/524542#M147957</guid>
      <dc:creator>pravinvram</dc:creator>
      <dc:date>2020-10-14T07:17:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to execute macro search with REST API</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-execute-macro-search-with-REST-API/m-p/524630#M147973</link>
      <description>&lt;P&gt;It looks like the macro is trying to execute, but the content requires permissions you don't have.&amp;nbsp; What are the search and macro trying to do?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Oct 2020 13:39:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-execute-macro-search-with-REST-API/m-p/524630#M147973</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-10-14T13:39:34Z</dc:date>
    </item>
  </channel>
</rss>

