I have inherited a Splunk system and this is one of the alerts
| metadata index=index-cc* type=hosts | eval age = now()-lastTime | where age > 86400 | sort age d | convert ctime(lastTime) | fields lastTime,host,source,age | rename age as "Seconds Since Last Event" | search `Exempted_Dark_Devices`
How do I find the file Exempted_Dark_Devices?
Thank you
From the syntax `Exempted_Dark_Devices`, it's a macro.
Look in the macro definitions and you should be able to find the expansion of this macro
https://docs.splunk.com/Documentation/Splunk/9.2.0/Knowledge/Definesearchmacros