Editing a Splunk macro that is provided by Z Operational Log and Data Analytics

You can update the Splunk macros that are provided with the IBM Z® Operational Log and Data Analytics application.

Procedure

  1. Log in to Splunk.
  2. Click Settings > Advanced search > Search macros.
  3. Set the App filter to IBM Z Operational Log and Data Analytics (ibm_zlda_insights), and select Created in the App.
  4. Click the name of a macro to edit.

    When you save the macro, the macros.conf file is stored as a local editable file. For information about editing a configuration file, see How to edit a configuration file in the Splunk documentation.