Answer by warren for Questions related to splunk builtin macros in correlation search

If you have access to the host(s) Splunk’s running on, you can find the definitions in $SPLUNK_HOME$/etc/*/macros.conf

If you don’t have that access, then it’s possible you don’t have permissions to see the definitions of those macros

However, you can always use the Job Inspector to see how Splunk translates what you type into what it runs

from User warren – Stack Overflow https://stackoverflow.com/questions/69275756/questions-related-to-splunk-builtin-macros-in-correlation-search/69287600#69287600
via IFTTT