Knowledge Management

macro with localop?

vbumgarner
Contributor

Is there any way to start a macro with a generator command? I get the error "The command must be the first command of a search."

Tags (1)
0 Karma
1 Solution

hazekamp
Builder

Vincent,

You can have macros that make use of generating commands, but the error is likely correct in that certain search commands (i.e. metadata) must be the first command of a search.

## macros.conf
[metadata]
definition = metadata type=hosts index=*
iseval = 0

## search
| `metadata`

View solution in original post

0 Karma

hazekamp
Builder

Vincent,

You can have macros that make use of generating commands, but the error is likely correct in that certain search commands (i.e. metadata) must be the first command of a search.

## macros.conf
[metadata]
definition = metadata type=hosts index=*
iseval = 0

## search
| `metadata`
0 Karma

gkanapathy
Splunk Employee
Splunk Employee

It is lame. Can you do it if you make it into an iseval=1 definition returning a string?

0 Karma

vbumgarner
Contributor

We figured that out, but it's kinda lame. It'd be nice to have the pipe in the definition.

0 Karma
Get Updates on the Splunk Community!

Get Inspired! We’ve Got Validation that Your Hard Work is Paying Off

We love our Splunk Community and want you to feel inspired by all your hard work! Eric Fusilero, our VP of ...

What's New in Splunk Enterprise 9.4: Features to Power Your Digital Resilience

Hey Splunky People! We are excited to share the latest updates in Splunk Enterprise 9.4. In this release we ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...