Getting Data In

how to add a timeformat for a search which contains an unique string in macros.conf?

pavanae
Builder

I have a search as follows

earliest="08/01/2016:00:00:01" latest="08/01/2016:23:59:59" getABCsWin("XYZ","abc12345678")

Now how can I add the time format string as mentioned below for all the searches contains unique search string "getABCsWin"

timeformat="%d/%m/%Y:%H:%M:%S”

Is it something I need to add in macros.conf if yes. How can I add it?

0 Karma
1 Solution

sundareshr
Legend

You can edit the getABCsWin macro from the GUI. All (permissions) macros can be found at Settings > Advanced Search > Search macros.

View solution in original post

0 Karma

sundareshr
Legend

You can edit the getABCsWin macro from the GUI. All (permissions) macros can be found at Settings > Advanced Search > Search macros.

0 Karma

pavanae
Builder

so in search macros do I need click new and add the macro?
Can you explain a little detail? I would really appreciate your help?

0 Karma

sundareshr
Legend

It looks like the macro already exists. When you click on "Search Macros", it will list all the macros. Find the one called getABCsWin edit the definition & save.

0 Karma

pavanae
Builder
0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...