Macros for the Splunk App for AWS
The Splunk App for AWS includes a set of macros that support dashboard performance. In most circumstances, you do not need to edit these macros.
Name | Default macro definition | Update required if you manage inputs from the add-on rather than the app |
---|---|---|
aws-cloudtrail-index | (index="main" OR index="aws-cloudtrail")
|
If you are using any index for your CloudTrail data other than main , aws-cloudtrail , or another default index you have set for your environment, add it to this definition.
|
aws-config-index | (index="main" OR index="aws-config")
|
If you are using any index for your Config data other than main , aws-config , or another default index you have set for your environment, add it to this definition.
|
aws-billing-index | (index="main" OR index="default")
|
If you are using any index for your Billing data other than main or another default index you have set for your environment, add it to this definition.
|
aws-cloudwatch-index | (index="main" OR index="default")
|
If you are using any index for your CloudWatch data other than main or another default index you have set for your environment, add it to this definition.
|
aws-description-index | (index="main" OR index="default")
|
If you are using any index for your Description data other than main , add it to this definition.
|
aws-config-rule-index | (index="main" OR index="default")
|
If you are using any index for your Config Rule data other than main , add it to this definition.
|
aws-inspector-index | (index="main" OR index="default")
|
If you are using any index for your Amazon Inspector data other than main , add it to this definition.
|
aws-s3-index | (index="main")
|
If you are using any indexes for your S3 access logs, ELB access logs, and CloudFront access logs other than main , add them to this definition.
|
aws-health-index | (index="main")
|
If you are using any index for your AWS Personal Health data other than main , add it to this definition.
|
aws-cloudwatch-logs-index | (index="main" OR index="default")
|
If you are using any indexes other than main for your CloudWatch Logs data, including any data that you collect through the add-on's Kinesis input, add it to this definition.
|
Data models for the Splunk App for AWS |
This documentation applies to the following versions of Splunk® App for AWS (Legacy): 5.1.0, 5.1.1, 5.1.2, 5.1.3
Feedback submitted, thanks!