Splunk Enterprise

Why the macro error when updated the cloudflare app on Splunk?

izzie123
Path Finder

Hello,

We are currently running splunk on 8.1 and we upgraded the cloudflare app for splunk to its latest version (2.0.0)

Although we see that the dashboards from the app is getting populated properly, we are getting this error related to the macro.

SearchParser - The search specifies a macro 'cloudflare_zt_index' that cannot be found. Reasons include: the macro name is misspelled, you do not have "read" permission for the macro, or the macro has not been shared with this application. Click Settings, Advanced search, Search Macros to view macro information.

We have given the macro global permissions, added a setting in the distsearch.conf to ensure the data replication but still the error is showing up.

We have disabled the app for now. However, we are trying to investigate, what would be the issue.

Kindly help

Labels (3)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...