Splunk Search

How to include arguments in search macros with non-alphanumeric values

cherrypick
Path Finder

I have arguments for my macro that contain other values e.g. $env:user$ and $timepicker.earliest$/$timepicker.latest$. How do I include these in my macro definition as it doesn't allow me since macro arguments must only contain alphanumeric, '_' and '-' characters?

 

 

Labels (1)
0 Karma
1 Solution

yuanliu
SplunkTrust
SplunkTrust

Use macro params to pass these tokens.  Here is an example:

NameDefinitionArguments
non-alphabetic-token(2)index=_internal earliest=$earliest_tok$ latest=$latest_tok$earliest_tok, latest_tok

 

<form version="1.1" theme="light">
  <label>Non-alphabetic tokens</label>
  <description>https://community.splunk.com/t5/Splunk-Search/How-to-include-arguments-in-search-macros-with-non-alphanumeric/m-p/696333#M236667</description>
  <fieldset submitButton="false">
    <input type="time" token="timepicker" searchWhenChanged="true">
      <label>pick time</label>
      <default>
        <earliest>-15m</earliest>
        <latest>now</latest>
      </default>
    </input>
  </fieldset>
  <row>
    <panel>
      <title>$timepicker.earliest$</title>
      <table>
        <search>
          <query>`non-alphabetic-token($timepicker.earliest$, $timepicker.latest$)`
| addinfo
| stats count by info_min_time info_max_time
| foreach info_*
    [eval &lt;&lt;FIELD&gt;&gt; = strftime(&lt;&lt;FIELD&gt;&gt;, "%F %T")]</query>
          <earliest>-24h@h</earliest>
          <latest>now</latest>
        </search>
        <option name="drilldown">none</option>
        <option name="refresh.display">progressbar</option>
      </table>
    </panel>
  </row>
</form>

 

Here are some sample interactions:

non-alphabetic-token-recent.png

non-alphabetic-token-past.png

  

View solution in original post

0 Karma

PickleRick
SplunkTrust
SplunkTrust

I'm not sure you understand the macros correctly.

if you define a macro with two parameters paramA and paramB it will get substituted in your search with whatever values you specify for them. These are separate layers.

0 Karma

yuanliu
SplunkTrust
SplunkTrust

Use macro params to pass these tokens.  Here is an example:

NameDefinitionArguments
non-alphabetic-token(2)index=_internal earliest=$earliest_tok$ latest=$latest_tok$earliest_tok, latest_tok

 

<form version="1.1" theme="light">
  <label>Non-alphabetic tokens</label>
  <description>https://community.splunk.com/t5/Splunk-Search/How-to-include-arguments-in-search-macros-with-non-alphanumeric/m-p/696333#M236667</description>
  <fieldset submitButton="false">
    <input type="time" token="timepicker" searchWhenChanged="true">
      <label>pick time</label>
      <default>
        <earliest>-15m</earliest>
        <latest>now</latest>
      </default>
    </input>
  </fieldset>
  <row>
    <panel>
      <title>$timepicker.earliest$</title>
      <table>
        <search>
          <query>`non-alphabetic-token($timepicker.earliest$, $timepicker.latest$)`
| addinfo
| stats count by info_min_time info_max_time
| foreach info_*
    [eval &lt;&lt;FIELD&gt;&gt; = strftime(&lt;&lt;FIELD&gt;&gt;, "%F %T")]</query>
          <earliest>-24h@h</earliest>
          <latest>now</latest>
        </search>
        <option name="drilldown">none</option>
        <option name="refresh.display">progressbar</option>
      </table>
    </panel>
  </row>
</form>

 

Here are some sample interactions:

non-alphabetic-token-recent.png

non-alphabetic-token-past.png

  

0 Karma

cherrypick
Path Finder

Amazing! Thank you. Yes I misunderstood macros.

0 Karma

cherrypick
Path Finder

Or is there another way to use re-usable SPL searches that can take these values into account?

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...