Knowledge Management

Macro Validation Expression Error?

jluo_splunk
Splunk Employee
Splunk Employee

I made a macro, we'll call it "test" defined as

 eval new_rate=$val$*$rate$

with the validation expression just checking rate to make sure it's a number

isnum($rate$)

When I call the macro.. I end up with something like test(revenue, .79) When I do this, Splunk says my rate failed validation because .79 is considered a string. When I pass 0.79, it passes as expected. Is this intentional, or a bug? Additionally, is there a function that would pass .79 as a number?

0 Karma
1 Solution

woodcock
Esteemed Legend

Like this:

test(revenue, tonumber(.79))

View solution in original post

0 Karma

woodcock
Esteemed Legend

Like this:

test(revenue, tonumber(.79))
0 Karma

jluo_splunk
Splunk Employee
Splunk Employee

Wonderful, thank you woodcock!

0 Karma

woodcock
Esteemed Legend

Note that I just retried all this in v6.5.0 and not only is tonumber not necessary but it generates an error now (the same error that this solution was proposed to solve)!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Introducing the 2026 - 2027 SplunkTrust cohort!

The goal of the SplunkTrust™ membership has historically been to acknowledge and recognize those who go above ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...