All Apps and Add-ons

Cacti Mirage Add-On for Cluster

aecruzp
Path Finder

regards

    We are currently trying to install this app in a cluster environment, but the following error is appearing.

[splunk-indexer-01-cnt] Streamed search execute failed because: Error in 'SearchParser': The search specifies a macro 'cacti_index' that can not be found. Reasons include: the macro name is misspelled, you do not have "read" permission for the macro, or the macro has not been shared with this application. Click Settings, Advanced search, Search Macros to view macro information.

   Tests have been made and installed this app in standalone only creating the index = cacti and we have no problems.

   Is there any recommendation in this regard? you only have to bundle the app in the master and deployer? must we change the file permissions? ...

   I'll be attentive to the comments

regards

0 Karma

mattymo
Splunk Employee
Splunk Employee

I would imagine that the macro doesn't exist on the indexers, or the permissions on the macro might be wrong?

Was the the app pushed to the indexer cluster?

When you are running your search, which app are you in?? Check if the macro permissions are global:

alt text

Its appears global in my instance.

the macro is technically not mandatory for your searches either, was just bet practice to allow the users to change it, so you could technically just not use it as well.

hit me up on slack if you are in the chat (splk.it/slack to sign up), I'm @mattymo

- MattyMo
0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...