Splunk Search

Macro Argument not applying

ebs
Communicator

Hi.

I've created the following macro: sessionCount(1)

With this definition:

datamodel Test summariesonly=true search | search "TEST.date"=$date$ | stats count(exchangeId)

But when I enter this search: | `sessionCount(2021-05-18)` it doesn't work

But this search does: | datamodel Test summariesonly=true search | search "TEST.date"=2021-05-18 | stats count(exchangeId)

 

What am I doing wrong?

Labels (2)
0 Karma
1 Solution

aasabatini
Motivator

Hi @ebs 

check if the macro is public or private, also check all the permissions

Regards

Alessandro

“The answer is out there, Neo, and it’s looking for you, and it will find you if you want it to.”

View solution in original post

0 Karma

aasabatini
Motivator

Hi @ebs 

check if the macro is public or private, also check all the permissions

Regards

Alessandro

“The answer is out there, Neo, and it’s looking for you, and it will find you if you want it to.”
0 Karma

ebs
Communicator

It seems it was a permissions issue, just took a while to propagate. Thank you!

0 Karma

ebs
Communicator

I fixed the permissions, but its still not working

0 Karma

aasabatini
Motivator

Hi @ebs 

Can you click on the searchand digit this sequence to expand the macro?

crtl+shift+e

New in 6.6, there is now a keystroke to expand macros in the search window! Click inside your search and press cmd-shift-E (on Mac, should be shift-WIN-E on Windows) and you'll see a window like this:

and please share the screen

Regards

Alessandro

“The answer is out there, Neo, and it’s looking for you, and it will find you if you want it to.”
0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...