<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Not getting result of splunk query in xsoar in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/not-getting-result-of-splunk-query-in-xsoar/m-p/537141#M1952</link>
    <description>&lt;P&gt;If certain Splunk apps have access to certain indexes you may have to define the Splunk app to use within the playbook task.&lt;/P&gt;</description>
    <pubDate>Thu, 30 Mar 2023 20:30:10 GMT</pubDate>
    <dc:creator>Joesephtorres</dc:creator>
    <dc:date>2023-03-30T20:30:10Z</dc:date>
    <item>
      <title>Not getting result of splunk query in xsoar</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/not-getting-result-of-splunk-query-in-xsoar/m-p/532161#M1833</link>
      <description>&lt;P&gt;I am trying one splunk query to fetch some result in xsoar using automation splunk-search, but I am not getting any result in xsoar whereas for the same query I am getting result in splunk, can anyone please help, below is the query:&lt;/P&gt;
&lt;P&gt;index=cbuae_windows | search&amp;nbsp; host IN(${incident.destinationhostname}) | stats values(Account_Domain) as Account_Domain,values(Account_Name) as Account_Name,values(EventCode) as EventCode,values(dest_nt_domain) as dest_nt_domain,values(signature) as signature,values(dest) as dest,earliest(_time) as earliest,latest(_time) as latest by user,src_user,action,host&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Feb 2023 06:29:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/not-getting-result-of-splunk-query-in-xsoar/m-p/532161#M1833</guid>
      <dc:creator>Himangi</dc:creator>
      <dc:date>2023-02-24T06:29:32Z</dc:date>
    </item>
    <item>
      <title>Re: Not getting result of splunk query in xsoar</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/not-getting-result-of-splunk-query-in-xsoar/m-p/537141#M1952</link>
      <description>&lt;P&gt;If certain Splunk apps have access to certain indexes you may have to define the Splunk app to use within the playbook task.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2023 20:30:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/not-getting-result-of-splunk-query-in-xsoar/m-p/537141#M1952</guid>
      <dc:creator>Joesephtorres</dc:creator>
      <dc:date>2023-03-30T20:30:10Z</dc:date>
    </item>
  </channel>
</rss>

