Hi @marios_kstone, we just had the same issue but were able to fix it with solution mentioned in here https://community.splunk.com/t5/Deployment-Architecture/Why-does-an-eventtype-calling-a-macro-only-fails-in-an-indexer/m-p/264195 Adding the macros.conf file to the replication bundle via distsearch.conf let the eventtypes for notable suppression appear again. /opt/splunk/etc/system/local/distsearch.conf [replicationSettings:refineConf] replicate.macros = true Regards, Daniel
... View more