- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
What is the use drop_dm_object_name() clause in a query with tstats.?
I am trying to find out what purpose drop_dm_object_name() serves.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/b5db7/b5db78eeb9daab00135c6d47ba91f077bf0ea8c0" alt="smoir_splunk smoir_splunk"
data:image/s3,"s3://crabby-images/1f594/1f594b1b4c0941863df1722dd52dd06a5b9a2e11" alt="Splunk Employee Splunk Employee"
That macro just changes the name of fields in data models to be just the field name, instead of the relative name in the data model. So a dataset would go from: Authentication.user to just "user" after using that macro.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
what is macro?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Search macros in Splunk are reusable chunks of Search Processing Language (SPL) that you can insert into other searches. It's enclosed within acute/back quotes `macro_name` on your search like `drop_dm_object_name(field)`. You can see these macros in Splunk and define them under Settings > Advanced Search > Search Macros.
All about macros here :
Use search macros in searches - Splunk Documentation
Hope this helps.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/457c1/457c1ae3509d8fe8563bd2d1802e4f565f69d549" alt="Keysofsandiego Keysofsandiego"
A macro is a rule that shows how a certain input should be mapped to a replacement output
To expand a macro in splunk - use CTRL + SHIFT + e
And to OP - drop_dm_object_name removes the leading stuff from a data model.
DM fields (not index, host, sourcetype etc) but the ones you create as custom all have leading words infront of the field.
In a typical authentication DM for example all the fields have a leading "Authentication." prefix.
Authentication.user, Authentication.tag, Authentication.app etc.
drop_dm_object just drops the "Authentication." part.
Cheers
data:image/s3,"s3://crabby-images/2762a/2762a549f4986b9f8f4e515ea77f65f7d9fa1fc8" alt=""