Knowledge Management

workflow action to polpulate macro

coreyf311
Path Finder

how to create a workflow action to populate a macro? Use a workflow action to grab hostname/IP from event and pass that to a macro for later use in follow on searches.

0 Karma
1 Solution

woodcock
Esteemed Legend

You would use the REST API to update a macro; here is an excellent answer on how to do that (be sure to UpVote him):
https://answers.splunk.com/answers/223843/rest-endpoint-for-modifying-applocalmacrosconf.html

View solution in original post

woodcock
Esteemed Legend

You would use the REST API to update a macro; here is an excellent answer on how to do that (be sure to UpVote him):
https://answers.splunk.com/answers/223843/rest-endpoint-for-modifying-applocalmacrosconf.html

Get Updates on the Splunk Community!

Splunk Enterprise Security 8.0.2 Availability: On cloud and On-premise!

A few months ago, we released Splunk Enterprise Security 8.0 for our cloud customers. Today, we are excited to ...

Logs to Metrics

Logs and Metrics Logs are generally unstructured text or structured events emitted by applications and written ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...