<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Macros not fetching data in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Macros-not-fetching-data/m-p/679573#M232326</link>
    <description>&lt;P&gt;I have a lookup which has fields like account_name, account_owner, environment etc. this lookup has more than 1000+ data. I created one macro under which write a search query below:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;search [| inputlookup Account_Owners.csv |rename "Account ID" as aws_account_id |search Environment IN (PROD, UAT, ) |table account_id]&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;After that whenever, I am calling this macros with an index it's not fetching whole log except very accounts. But when I'm passing the lookup query directly into search with same index it's populating every logs&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 05 Mar 2024 11:18:36 GMT</pubDate>
    <dc:creator>sinhashubham014</dc:creator>
    <dc:date>2024-03-05T11:18:36Z</dc:date>
    <item>
      <title>Macros not fetching data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Macros-not-fetching-data/m-p/679573#M232326</link>
      <description>&lt;P&gt;I have a lookup which has fields like account_name, account_owner, environment etc. this lookup has more than 1000+ data. I created one macro under which write a search query below:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;search [| inputlookup Account_Owners.csv |rename "Account ID" as aws_account_id |search Environment IN (PROD, UAT, ) |table account_id]&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;After that whenever, I am calling this macros with an index it's not fetching whole log except very accounts. But when I'm passing the lookup query directly into search with same index it's populating every logs&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Mar 2024 11:18:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Macros-not-fetching-data/m-p/679573#M232326</guid>
      <dc:creator>sinhashubham014</dc:creator>
      <dc:date>2024-03-05T11:18:36Z</dc:date>
    </item>
    <item>
      <title>Re: Macros not fetching data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Macros-not-fetching-data/m-p/679678#M232355</link>
      <description>&lt;P&gt;I have a suspicion that you misspelled either &lt;U&gt;account_id&lt;/U&gt; or &lt;U&gt;aws_account_id&lt;/U&gt; in the macro because the way you presented, the resultant subsearch is &lt;FONT face="courier new,courier"&gt;NOT ()&lt;/FONT&gt;. &amp;nbsp;Are you sure you copied the above search verbatim into index search and you get the correct result that is NOT the same as using the macro?&lt;/P&gt;&lt;P&gt;Further, which fieldname exists in actual data? aws_account_id or account_id? &amp;nbsp;For example, if &lt;EM&gt;account_id&lt;/EM&gt; exists AND if you intend to match &lt;U&gt;account_id&lt;/U&gt; in index data with "&lt;U&gt;Account ID&lt;/U&gt;" in the lookup, your macro should be something like&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;search [inputlookup Account_Owners.csv |rename "Account ID" as account_id |search Environment IN (PROD, UAT, ) |table account_id]&lt;/LI-CODE&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Mar 2024 00:02:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Macros-not-fetching-data/m-p/679678#M232355</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2024-03-06T00:02:09Z</dc:date>
    </item>
  </channel>
</rss>

