Splunk® App for Splunk Attack Analyzer

User Guide

Acrobat logo Download manual as PDF


Acrobat logo Download topic as PDF

Configure macros in the Splunk App for Splunk Attack Analyzer

The Splunk App for Splunk Attack Analyzer ships with a configured macro that serves as the basis from which the app dashboards operate. The macro has these default configurations:

  • Macro name: saa_indexes
  • Definition: index="main"
  • Index: main

If you manage inputs from the add-on rather than the app, or if you are using any index for your Splunk Attack Analyzer data other than the main index or another default index you set for your environment, add those inputs or indexes to the macro definition.

If the Splunk Attack Analyzer data is flowing into an index other than the main index, follow the steps to reconfigure the macro.

Reconfigure the macro

To change the macro definition, perform the following steps on all search heads:

  1. Navigate to Settings and then to Advanced search.
  2. Select Search macros.
  3. From the list of apps, select Splunk App for Splunk Attack Analyzer (saa_indexes).
  4. Set the list by Owner to Any and Created in App.
  5. Select saa_indexes. This opens the definition page of saa_indexes.
  6. In Definition, change the index to the name of the index where Splunk Attack Analyzer data is flowing in. For example, if the Splunk Attack Analyzer data is flowing into the index named saa, the definition is index=saa.
  7. Select Save to save your changes.
Last modified on 29 August, 2023
PREVIOUS
Install the Splunk App for Splunk Attack Analyzer
  NEXT
Dashboards included with the Splunk App for Splunk Attack Analyzer

This documentation applies to the following versions of Splunk® App for Splunk Attack Analyzer: 1.0.0, 1.1.0, 1.1.1


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters