Splunk Enterprise Security

What is the use drop_dm_object_name() clause in a query with tstats.?

Abhi89
New Member

I am trying to find out what purpose drop_dm_object_name() serves.

0 Karma

smoir_splunk
Splunk Employee
Splunk Employee

That macro just changes the name of fields in data models to be just the field name, instead of the relative name in the data model. So a dataset would go from: Authentication.user to just "user" after using that macro.

0 Karma

Jishnukn10
New Member

what is macro?

0 Karma

kkrises
Path Finder

@Jishnukn10 - 

Search macros in Splunk are reusable chunks of Search Processing Language (SPL) that you can insert into other searches. It's enclosed within acute/back quotes `macro_name` on your search like  `drop_dm_object_name(field)`. You can see these macros in Splunk and define them under Settings > Advanced Search > Search Macros.

All about macros here : 

Use search macros in searches - Splunk Documentation

Hope this helps. 

0 Karma

Keysofsandiego
Path Finder

A macro is a rule that shows how a certain input should be mapped to a replacement output

To expand a macro in splunk - use CTRL + SHIFT + e

And to OP - drop_dm_object_name removes the leading stuff from a data model.
DM fields (not index, host, sourcetype etc) but the ones you create as custom all have leading words infront of the field.
In a typical authentication DM for example all the fields have a leading "Authentication." prefix.
Authentication.user, Authentication.tag, Authentication.app etc.
drop_dm_object just drops the "Authentication." part.

Cheers

 

 

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...