Splunk Enterprise

Why the macro error when updated the cloudflare app on Splunk?

izzie123
Path Finder

Hello,

We are currently running splunk on 8.1 and we upgraded the cloudflare app for splunk to its latest version (2.0.0)

Although we see that the dashboards from the app is getting populated properly, we are getting this error related to the macro.

SearchParser - The search specifies a macro 'cloudflare_zt_index' that cannot be found. Reasons include: the macro name is misspelled, you do not have "read" permission for the macro, or the macro has not been shared with this application. Click Settings, Advanced search, Search Macros to view macro information.

We have given the macro global permissions, added a setting in the distsearch.conf to ensure the data replication but still the error is showing up.

We have disabled the app for now. However, we are trying to investigate, what would be the issue.

Kindly help

Labels (3)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...