Splunk Search

Filter Particar results from Macros

alex4
Loves-to-Learn Lots

Below query i am using to get the list of all indexes

| eventcount summarize=false index=* | dedup index | fields index

 `dm_mapped_indexes` This macros contain the list of indexes. 

Now i want to filter all the indexes from these macros " `dm_mapped_indexes`" and get all the other indexes.

Labels (4)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

It depends on what your macro expands to, but try this

| search NOT `dm_mapped_indexes`

Otherwise, please provide more details, e.g. a cut-down, sanitised version of your macro.

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...