Hello Guys,
Good Day!!
Can anyone please help me with a question that I have. Can I use a macro in the event type in Splunk. I am trying but looks like there is some issue.
A very small example, in my eventtype
[abcEventType]
search = index=`index`
and in the query behind my panel I have:
eventtype=abcEventType
| stats count
I am on Splunk on prem version 8.1.0.1
Thanks
You said there is an issue. What is it?