mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
1.9 KiB
1.9 KiB
Macro Manifest Schema
https://api.splunkresearch.com/schemas/macros.json
An object that defines the parameters for a Splunk Macro
| Abstract | Extensible | Status | Identifiable | Custom Properties | Additional Properties | Defined In |
|---|---|---|---|---|---|---|
| Can be instantiated | No | Experimental | No | Forbidden | Permitted |
Macro Manifest Properties
| Property | Type | Required | Nullable | Defined by |
|---|---|---|---|---|
| arguments | string[] |
Optional | No | Macro Manifest (this schema) |
| definition | string |
Optional | No | Macro Manifest (this schema) |
| description | string |
Required | No | Macro Manifest (this schema) |
| name | string |
Required | No | Macro Manifest (this schema) |
* |
any | Additional | Yes | this schema allows additional properties |
arguments
A list of the arguments being passed to this macro
arguments
- is optional
- type:
string[] - at least
0items in the array - defined in this schema
arguments Type
Array type: string[]
All items must be of the type:
string
definition
The macro definition
definition
- is optional
- type:
string - defined in this schema
definition Type
string
definition Example
"(query=fls-na* AND query = www* AND query=images*)"
description
What the macro is intended to filter
description
- is required
- type:
string - defined in this schema
description Type
string
description Example
"Use this macro to filter out known good objects"
name
The name of the macro
name
- is required
- type:
string - defined in this schema
name Type
string
name Example
"detection_search_output_filter"