I have a dashboard with multiple panels. Each panel has a different search, which i want to replace with a macro.
The problem is, i want to be able to filter with tokens.
My question is, can i have a Macro that has token values within it, that can be passed from the inputs on the dashboard.
Macro "Username ": index=ad source=userscan username=$username$
Dashboard input token = $username$
Panel search: "Username"
I cannot currently get this to work. Wondering do i need to do something another way?
You could pass arguments to macro like
Please have a look : https://docs.splunk.com/Documentation/Splunk/7.1.1/Knowledge/Searchmacroexamples