Splunk Search

How to pass key & value array into macro?

koshyk
Super Champion

Just checking if there is a smart way of passing "key" and "value" (ideally key-value array) into a macro

Ideally i'm looking for

## mykeyValueArray={key1:value1, key2:value2} 
[my_macro(1)]
args = mykeyValueArray
definition = index=abc sourcetype=xyz  $mykeyValueArray$

or atleast something like below as a baby-step

[my_macro(2)]
args = mykey,myvalue
definition = index=abc sourcetype=xyz  $mykey$=$myvalue$

we need to dynamically pass keys & values into the macro

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

The latter method should work.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

The latter method should work.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Full-Stack Security in Financial Services: AppDynamics, Cisco Secure Application, and ...

Full-Stack Security in Financial Services: AppDynamics, Cisco Secure Application, and Splunk ES Protecting a ...

It's Customer Success Time at .conf25

Hello Splunkers,   Ready for .conf25? The customer success and experience team is and can’t wait to see you ...

Pro Tips for First-Time .conf Attendees: Advice from SplunkTrust

Heading to your first .Conf? You’re in for an unforgettable ride — learning, networking, swag collecting, ...