Knowledge Management

Create search macro with return value

yko84109
Loves-to-Learn

Hi,

I want to create my search macro to return new field.
Example:

my_search_macro("1")

I want to return a new field, test, that contains "your value is " + $arg$

What I'm tried to write in search macro definition:

|eval test="your value is " + $arg$

But when I execute my search command as follow:

|makeresults | eval msg = my_search_macro("1") | table msg

I got an error.
So how can I simply create search macro with return value?

Thanks

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Macros are simple text substitutions, not functions. Your example query expands to | makeresults | eval msg = eval test="your value is foo" | table msg, which is why you get an error. Try changing the macro to "your value is " + $arg$ and be sure to check the "eval" box.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...