Getting Data In

how to add a timeformat for a search which contains an unique string in macros.conf?

pavanae
Builder

I have a search as follows

earliest="08/01/2016:00:00:01" latest="08/01/2016:23:59:59" getABCsWin("XYZ","abc12345678")

Now how can I add the time format string as mentioned below for all the searches contains unique search string "getABCsWin"

timeformat="%d/%m/%Y:%H:%M:%S”

Is it something I need to add in macros.conf if yes. How can I add it?

0 Karma
1 Solution

sundareshr
Legend

You can edit the getABCsWin macro from the GUI. All (permissions) macros can be found at Settings > Advanced Search > Search macros.

View solution in original post

0 Karma

sundareshr
Legend

You can edit the getABCsWin macro from the GUI. All (permissions) macros can be found at Settings > Advanced Search > Search macros.

0 Karma

pavanae
Builder

so in search macros do I need click new and add the macro?
Can you explain a little detail? I would really appreciate your help?

0 Karma

sundareshr
Legend

It looks like the macro already exists. When you click on "Search Macros", it will list all the macros. Find the one called getABCsWin edit the definition & save.

0 Karma

pavanae
Builder
0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Now On-Demand Join us to learn more about how you can leverage Service Level Objectives (SLOs) and the new ...

Database Performance Sidebar Panel Now on APM Database Query Performance & Service ...

We’ve streamlined the troubleshooting experience for database-related service issues by adding a database ...

IM Landing Page Filter - Now Available

We’ve added the capability for you to filter across the summary details on the main Infrastructure Monitoring ...