Splunk Enterprise Security

Macro

SN1
Path Finder

Hi I have this search

| `es_notable_events` | search timeDiff_type=current | timechart minspan=30m sum(count) as count by security_domain

when I am searching macro  `es_notable_events` it is not showing any result for all apps and any owner but the search is giving results and when running macro it is also showing results.

0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

Try removing the back ticks when you are searching for a macro.

Check the permissions on the macro

Use <ctrl><shft>E while your cursor is in the search box to expand the macro to check it is doing what you expect

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust

Please expand on what you mean for each scenario when you are getting results and when you are not getting results?

If there are multiple commands in your SPL, try removing them one at a time until the situation changes, so you can identify the step which is causing the issue.

0 Karma

SN1
Path Finder

every command is giving results thats not the problem , problem the macro which is used in this search when i am searching this macro it is giving me no result.

SN1_0-1740402645077.png

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Try removing the back ticks when you are searching for a macro.

Check the permissions on the macro

Use <ctrl><shft>E while your cursor is in the search box to expand the macro to check it is doing what you expect

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Data Management Digest – September 2026

    Welcome to the September 2026 edition of Data Management Digest! September brought a fresh wave of ...

Federated Search for CloudWatch Unified Data Store Is Generally Available

As organizations modernize their cloud environments, AWS workloads generate more security, operational, and ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...