<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: eventtype which contains macro is not working in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/eventtype-which-contains-macro-is-not-working/m-p/325349#M174932</link>
    <description>&lt;P&gt;There was an actual bug in Splunk for a while that was preventing this from working. I don't know if it was ever officially fixed or not, but I gave up on using macros in eventtypes being that everything seemed to be brittle or unreliable.&lt;/P&gt;

&lt;P&gt;Last time I heard others discussing it, they seemed to indicate it was still an issue.&lt;/P&gt;</description>
    <pubDate>Wed, 12 Apr 2017 10:33:41 GMT</pubDate>
    <dc:creator>rjthibod</dc:creator>
    <dc:date>2017-04-12T10:33:41Z</dc:date>
    <item>
      <title>eventtype which contains macro is not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/eventtype-which-contains-macro-is-not-working/m-p/325348#M174931</link>
      <description>&lt;P&gt;Hi Splunkers,&lt;/P&gt;

&lt;P&gt;I have distributed environment. when I tried searching for eventtype which contains macro is not working.&lt;/P&gt;

&lt;P&gt;I have seen docs saying that macros are by default skipped from search head  knowledge bundle. But, I have added distsearch.conf in TA where eventtype resides and I can see macros.conf in knowledge bundle getting replicated to search peers. still I am not able to get results from eventtype . when I expand eventtype in search showing results. &lt;/P&gt;

&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2017 08:48:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/eventtype-which-contains-macro-is-not-working/m-p/325348#M174931</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2017-04-12T08:48:51Z</dc:date>
    </item>
    <item>
      <title>Re: eventtype which contains macro is not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/eventtype-which-contains-macro-is-not-working/m-p/325349#M174932</link>
      <description>&lt;P&gt;There was an actual bug in Splunk for a while that was preventing this from working. I don't know if it was ever officially fixed or not, but I gave up on using macros in eventtypes being that everything seemed to be brittle or unreliable.&lt;/P&gt;

&lt;P&gt;Last time I heard others discussing it, they seemed to indicate it was still an issue.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2017 10:33:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/eventtype-which-contains-macro-is-not-working/m-p/325349#M174932</guid>
      <dc:creator>rjthibod</dc:creator>
      <dc:date>2017-04-12T10:33:41Z</dc:date>
    </item>
    <item>
      <title>Re: eventtype which contains macro is not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/eventtype-which-contains-macro-is-not-working/m-p/325350#M174933</link>
      <description>&lt;P&gt;What version of splunk are you using?&lt;/P&gt;

&lt;P&gt;If you're on 6.5.x, upgrade to 6.5.3: &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.5.3/ReleaseNotes/6.5.3#Uncategorized_issues"&gt;http://docs.splunk.com/Documentation/Splunk/6.5.3/ReleaseNotes/6.5.3#Uncategorized_issues&lt;/A&gt;&lt;BR /&gt;
If you're on 6.4.x, wait for 6.4.7 (allegedly).&lt;BR /&gt;
If you're on 6.3.x, upgrade to 6.5.3 &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;
If you're on 6.2.x or earlier, eventtypes with macros should work.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2017 10:42:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/eventtype-which-contains-macro-is-not-working/m-p/325350#M174933</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2017-04-12T10:42:52Z</dc:date>
    </item>
    <item>
      <title>Re: eventtype which contains macro is not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/eventtype-which-contains-macro-is-not-working/m-p/325351#M174934</link>
      <description>&lt;P&gt;Thanks Martin_mueller..&lt;/P&gt;

&lt;P&gt;Running on 6.5.2. I will update my splunk to latest version.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2017 12:26:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/eventtype-which-contains-macro-is-not-working/m-p/325351#M174934</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2017-04-12T12:26:24Z</dc:date>
    </item>
    <item>
      <title>Re: eventtype which contains macro is not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/eventtype-which-contains-macro-is-not-working/m-p/325352#M174935</link>
      <description>&lt;P&gt;Yes, It was listed and fixed in splunk latest version.&lt;/P&gt;

&lt;P&gt;find comment below from martin_mueller&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2017 12:27:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/eventtype-which-contains-macro-is-not-working/m-p/325352#M174935</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2017-04-12T12:27:35Z</dc:date>
    </item>
    <item>
      <title>Re: eventtype which contains macro is not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/eventtype-which-contains-macro-is-not-working/m-p/325353#M174936</link>
      <description>&lt;P&gt;We are running Splunk 7.0.3, in a distributed setting.&lt;/P&gt;

&lt;P&gt;On a search cluster running Splunk Enterprise Security, we added the SentenilOne TA, made it work inside ES to search with a macro (s1_index) defined in the TA.&lt;/P&gt;

&lt;P&gt;However, when searching in ES with "tag=malware" which pulls in that macro, we get these error messages from our indexers:&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;Error in 'SearchParser': The search specifies a macro 's1_index' that cannot be found. Reasons include: the macro name is misspelled, you do not have "read" permission for the macro, or the macro has not been shared with this application. Click Settings, Advanced search, Search Macros to view macro information.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;Inspecting the search job, I find this in the "remoteSearch":&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;( `s1_index` sourcetype=threat )
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;That seems to mean that the macro is not expanded locally before dispatch, nor is the macro definition included in the search bundle.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jun 2018 21:03:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/eventtype-which-contains-macro-is-not-working/m-p/325353#M174936</guid>
      <dc:creator>ww9rivers</dc:creator>
      <dc:date>2018-06-28T21:03:17Z</dc:date>
    </item>
    <item>
      <title>Re: eventtype which contains macro is not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/eventtype-which-contains-macro-is-not-working/m-p/325354#M174937</link>
      <description>&lt;P&gt;Did you configure distsearch.conf as mentioned in the question? &lt;/P&gt;</description>
      <pubDate>Fri, 29 Jun 2018 06:34:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/eventtype-which-contains-macro-is-not-working/m-p/325354#M174937</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2018-06-29T06:34:17Z</dc:date>
    </item>
    <item>
      <title>Re: eventtype which contains macro is not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/eventtype-which-contains-macro-is-not-working/m-p/325355#M174938</link>
      <description>&lt;P&gt;Yes. I have added this stanza in the &lt;CODE&gt;distsearch.conf&lt;/CODE&gt; file:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[replicationSettings:refineConf]
replicate.macros = true
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 12 Jul 2018 19:19:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/eventtype-which-contains-macro-is-not-working/m-p/325355#M174938</guid>
      <dc:creator>ww9rivers</dc:creator>
      <dc:date>2018-07-12T19:19:02Z</dc:date>
    </item>
    <item>
      <title>Re: eventtype which contains macro is not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/eventtype-which-contains-macro-is-not-working/m-p/325356#M174939</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
I am also facing the same issue in Splunk 7.1.1 version.i tried adding config in distsearch.conf as well.still doe not work out.Do you have the resolution for this ?&lt;/P&gt;</description>
      <pubDate>Tue, 24 Sep 2019 05:40:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/eventtype-which-contains-macro-is-not-working/m-p/325356#M174939</guid>
      <dc:creator>sujanay02</dc:creator>
      <dc:date>2019-09-24T05:40:39Z</dc:date>
    </item>
  </channel>
</rss>

