Knowledge Management

workflow action to polpulate macro

coreyf311
Path Finder

how to create a workflow action to populate a macro? Use a workflow action to grab hostname/IP from event and pass that to a macro for later use in follow on searches.

0 Karma
1 Solution

woodcock
Esteemed Legend

You would use the REST API to update a macro; here is an excellent answer on how to do that (be sure to UpVote him):
https://answers.splunk.com/answers/223843/rest-endpoint-for-modifying-applocalmacrosconf.html

View solution in original post

woodcock
Esteemed Legend

You would use the REST API to update a macro; here is an excellent answer on how to do that (be sure to UpVote him):
https://answers.splunk.com/answers/223843/rest-endpoint-for-modifying-applocalmacrosconf.html

Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and stall ...

Print, Leak, Repeat: UEBA Insider Threats You Can't Ignore

Are you ready to uncover the threats hiding in plain sight? Join us for "Print, Leak, Repeat: UEBA Insider ...

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...