Splunk Search

What is the root cause of the message preventing saving a search: "Error in 'SearchParser': The search specifies a macro.."

landen99
Motivator

What is the root cause of the message preventing saving a search:
alt text
Error in 'SearchParser': The search specifies a macro..
This error started appearing after a migration from an old SHC to a new SHC.

The resolution was to move the macro to the same app as the search, even though it was set to Global sharing, but that doesn't explain the root cause. The error returns when the macro is moved back to the original app.

Tags (1)
0 Karma

jpolvino
Builder

What happens when you grab that search and run it on its own in the app, with the macro in its native location set as global?

Same as above, but with the macro homed to the app you're running from?

One test in each case is to expand all the macros with Control-Shift-E. Might take a minute.

When I'm in app "A" and do Control-Shift-E on a macro from app "B" that is shared global (with Everyone=Read, Power=Write) it expands and works fine.

Finally, check your App permissions (where the macro lives). Mine says Everyone=Read, Power=Write, and the bottom radio button is true.

0 Karma

landen99
Motivator

The macro works fine at the SPL line. Permissions are global.

0 Karma

niketn
Legend

@landen99 if you put back the SPL for macro wildfire do the other macros work? Have you checked permission/app for other macros and compare them with wildfire in case others work?

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...