All Apps and Add-ons

How to modify macros.conf to include multiple indexes

cisaksen
Explorer

How do I modify marcos.conf to include multiple indexes ? Will it recognize wildcards in the index name?

example:

   [event_sources]
    definition = (index="win*" OR source=*WinEventLog*)
    disabled = 0

cisaksen
Explorer

Thanks for the reply, but i found that the above syntax is actually working there are other issues as to why i'm not seeing what I think I should be.

Thanks again

0 Karma

manjunathmeti
SplunkTrust
SplunkTrust

Yes, search macros can include base search terms. It will recognize wildcards in index name.

From Splunk documentation:
Search macros are reusable chunks of Search Processing Language (SPL) that you can insert into other searches. Search macros can be any part of a search, such as an eval statement or search term and do not need to be a complete command. You can also specify whether the macro field takes any arguments.

0 Karma
Get Updates on the Splunk Community!

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...