Splunk Enterprise Security

Macro

SN1
Path Finder

Hi I have this search

| `es_notable_events` | search timeDiff_type=current | timechart minspan=30m sum(count) as count by security_domain

when I am searching macro  `es_notable_events` it is not showing any result for all apps and any owner but the search is giving results and when running macro it is also showing results.

0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

Try removing the back ticks when you are searching for a macro.

Check the permissions on the macro

Use <ctrl><shft>E while your cursor is in the search box to expand the macro to check it is doing what you expect

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust

Please expand on what you mean for each scenario when you are getting results and when you are not getting results?

If there are multiple commands in your SPL, try removing them one at a time until the situation changes, so you can identify the step which is causing the issue.

0 Karma

SN1
Path Finder

every command is giving results thats not the problem , problem the macro which is used in this search when i am searching this macro it is giving me no result.

SN1_0-1740402645077.png

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Try removing the back ticks when you are searching for a macro.

Check the permissions on the macro

Use <ctrl><shft>E while your cursor is in the search box to expand the macro to check it is doing what you expect

First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

OpenTelemetry for Legacy Apps? Yes, You Can!

This article is a follow-up to my previous article posted on the OpenTelemetry Blog, "Your Critical Legacy App ...

UCC Framework: Discover Developer Toolkit for Building Technology Add-ons

The Next-Gen Toolkit for Splunk Technology Add-on Development The Universal Configuration Console (UCC) ...

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...