We have a realtime search which will fire alerts based on some thresholds which we currently store in macros
So I will dumb down the realtime savedsearch as an example
sourcetype="myData" | head 2 | eval testMacro = `macroThreshold` | where testMacro > 120
We have setup page for our app which allows modification of these macros (can also be done via management)
macros.conf looks something like this
definition = 100
Now the saved search is a realtime search and we are hoping that if someone changes the definition of macroThreshold it will be updated in the realtime search. This doesnt appear to work and it appears to be fixed as the value the macro was when the search was started.
Does anyone have an alternate way for changing this threshold and having it used by the realtime search?
A subsearch will not work as you cannot have realtime subsearches.
Is there a way to force/kill the realtime search to restart using this new value?