All Apps and Add-ons

How to modify macros.conf to include multiple indexes

cisaksen
Explorer

How do I modify marcos.conf to include multiple indexes ? Will it recognize wildcards in the index name?

example:

   [event_sources]
    definition = (index="win*" OR source=*WinEventLog*)
    disabled = 0

cisaksen
Explorer

Thanks for the reply, but i found that the above syntax is actually working there are other issues as to why i'm not seeing what I think I should be.

Thanks again

0 Karma

manjunathmeti
Champion

Yes, search macros can include base search terms. It will recognize wildcards in index name.

From Splunk documentation:
Search macros are reusable chunks of Search Processing Language (SPL) that you can insert into other searches. Search macros can be any part of a search, such as an eval statement or search term and do not need to be a complete command. You can also specify whether the macro field takes any arguments.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...