Getting Data In

how to add a timeformat for a search which contains an unique string in macros.conf?

pavanae
Builder

I have a search as follows

earliest="08/01/2016:00:00:01" latest="08/01/2016:23:59:59" getABCsWin("XYZ","abc12345678")

Now how can I add the time format string as mentioned below for all the searches contains unique search string "getABCsWin"

timeformat="%d/%m/%Y:%H:%M:%S”

Is it something I need to add in macros.conf if yes. How can I add it?

0 Karma
1 Solution

sundareshr
Legend

You can edit the getABCsWin macro from the GUI. All (permissions) macros can be found at Settings > Advanced Search > Search macros.

View solution in original post

0 Karma

sundareshr
Legend

You can edit the getABCsWin macro from the GUI. All (permissions) macros can be found at Settings > Advanced Search > Search macros.

0 Karma

pavanae
Builder

so in search macros do I need click new and add the macro?
Can you explain a little detail? I would really appreciate your help?

0 Karma

sundareshr
Legend

It looks like the macro already exists. When you click on "Search Macros", it will list all the macros. Find the one called getABCsWin edit the definition & save.

0 Karma

pavanae
Builder
0 Karma
Get Updates on the Splunk Community!

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

Register Join this Tech Talk to learn how unique features like Service Centric Views, Tag Spotlight, and ...