Splunk Enterprise Security

Macro

SN1
Path Finder

Hi I have this search

| `es_notable_events` | search timeDiff_type=current | timechart minspan=30m sum(count) as count by security_domain

when I am searching macro  `es_notable_events` it is not showing any result for all apps and any owner but the search is giving results and when running macro it is also showing results.

0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

Try removing the back ticks when you are searching for a macro.

Check the permissions on the macro

Use <ctrl><shft>E while your cursor is in the search box to expand the macro to check it is doing what you expect

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust

Please expand on what you mean for each scenario when you are getting results and when you are not getting results?

If there are multiple commands in your SPL, try removing them one at a time until the situation changes, so you can identify the step which is causing the issue.

0 Karma

SN1
Path Finder

every command is giving results thats not the problem , problem the macro which is used in this search when i am searching this macro it is giving me no result.

SN1_0-1740402645077.png

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Try removing the back ticks when you are searching for a macro.

Check the permissions on the macro

Use <ctrl><shft>E while your cursor is in the search box to expand the macro to check it is doing what you expect

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...