Splunk Enterprise

Why the macro error when updated the cloudflare app on Splunk?

izzie123
Path Finder

Hello,

We are currently running splunk on 8.1 and we upgraded the cloudflare app for splunk to its latest version (2.0.0)

Although we see that the dashboards from the app is getting populated properly, we are getting this error related to the macro.

SearchParser - The search specifies a macro 'cloudflare_zt_index' that cannot be found. Reasons include: the macro name is misspelled, you do not have "read" permission for the macro, or the macro has not been shared with this application. Click Settings, Advanced search, Search Macros to view macro information.

We have given the macro global permissions, added a setting in the distsearch.conf to ensure the data replication but still the error is showing up.

We have disabled the app for now. However, we are trying to investigate, what would be the issue.

Kindly help

Labels (3)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud’s AI Assistant in Action Series: Analyzing and ...

This is the second post in our Splunk Observability Cloud’s AI Assistant in Action series, in which we look at ...

Elevate Your Organization with Splunk’s Next Platform Evolution

 Thursday, July 10, 2025  |  11AM PDT / 2PM EDT Whether you're managing complex deployments or looking to ...

Splunk Answers Content Calendar, June Edition

Get ready for this week’s post dedicated to Splunk Dashboards! We're celebrating the power of community by ...