Dashboards & Visualizations

How to know where the macro is used ?

zacksoft_wf
Contributor

we have a lot of contents/knoweldge objects and are trying to weed out the ones that are unused. We are using Enterprise Security and other apps. 
I have identified a few `Macros`  that I want to remove/delete, but before that I want to make sure that they are not used in any Splunk Saved search/correlation search/loop up generating search Or within any SPL for that matter.
Is there a way to find it ?

Tags (1)
0 Karma
1 Solution

kamlesh_vaghela
SplunkTrust
SplunkTrust

@zacksoft_wf 

You can use these also for identifying use of macros.

| rest /services/saved/searches | table search | search search="*<<ENTER_MACRO_NAME>>*"
| rest/servicesNS/-/-/data/ui/views | table "eai:data" | search "eai:data"="*<<ENTER_MACRO_NAME>>*"

 

KV

View solution in original post

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@zacksoft_wf 

You can use these also for identifying use of macros.

| rest /services/saved/searches | table search | search search="*<<ENTER_MACRO_NAME>>*"
| rest/servicesNS/-/-/data/ui/views | table "eai:data" | search "eai:data"="*<<ENTER_MACRO_NAME>>*"

 

KV

0 Karma

codebuilder
Influencer

You can use the REST endpoint.

| rest/servicesNS/-/-/data/lookup-table-files
----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...