Knowledge Management

Editing macro is giving a 404 error

ffr03
Explorer

When I tried to edit a macro in Settings\all Settings it is giving a 404

alt text

It seems the generated URL usees ../data/.. it should be ../admin/ , is there any way to fix the render url to use the /admin/ instead of /data/?

Thanks

Tags (2)

Forseti_
Engager

2 years in and I am facing this issue now also, however going to settings -> advanced search -> search no longer works either.

Chaning /data/ to /admin/ does the trick however

0 Karma

ashutoshab
Communicator

I have faced the issue on many occasions. Earlier I used to bang my head facing this issue as it never allows to edit the macro seamlessly. This seems like an issue with App Permissions. But, now I never jump to 'All Configurations' windows and search the Macro there, instead I visit Advanced Search >> Macros.

What I assume, when we jump to Advanced Setting from the Current app, it sets the context of the app which is selected and if the macro has permissions restricted to a particular app, Splunk will not let you edit the configuration.

So, I always prefer, Advanced Search >> Macros way.

madcitygeek
Explorer

Doesn't fix the bug, but accessing via settings -> advanced search -> search macros works for editing macros.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

Another quarter, another wave of innovation. From complex integrations to pushing the limits ...

Federated Search for Dynamic Data Self Storage Is Now Generally Available on Splunk ...

 Splunk is excited to announce the General Availability of Federated Search for Dynamic Data Self Storage ...

Index This | What has many keys but can’t unlock a door?

July 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...