I am trying one splunk query to fetch some result in xsoar using automation splunk-search, but I am not getting any result in xsoar whereas for the same query I am getting result in splunk, can anyone please help, below is the query:
index=cbuae_windows | search host IN(${incident.destinationhostname}) | stats values(Account_Domain) as Account_Domain,values(Account_Name) as Account_Name,values(EventCode) as EventCode,values(dest_nt_domain) as dest_nt_domain,values(signature) as signature,values(dest) as dest,earliest(_time) as earliest,latest(_time) as latest by user,src_user,action,host
... View more