Splunk Enterprise Security

Macro

SN1
Path Finder

Hi I have this search

| `es_notable_events` | search timeDiff_type=current | timechart minspan=30m sum(count) as count by security_domain

when I am searching macro  `es_notable_events` it is not showing any result for all apps and any owner but the search is giving results and when running macro it is also showing results.

0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

Try removing the back ticks when you are searching for a macro.

Check the permissions on the macro

Use <ctrl><shft>E while your cursor is in the search box to expand the macro to check it is doing what you expect

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust

Please expand on what you mean for each scenario when you are getting results and when you are not getting results?

If there are multiple commands in your SPL, try removing them one at a time until the situation changes, so you can identify the step which is causing the issue.

0 Karma

SN1
Path Finder

every command is giving results thats not the problem , problem the macro which is used in this search when i am searching this macro it is giving me no result.

SN1_0-1740402645077.png

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Try removing the back ticks when you are searching for a macro.

Check the permissions on the macro

Use <ctrl><shft>E while your cursor is in the search box to expand the macro to check it is doing what you expect

First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...