Skip to main content
All CollectionsTemplatesBasic
Simple Splunk Query with Optional Return Field Filters - Workflow Template
Simple Splunk Query with Optional Return Field Filters - Workflow Template

A simple Splunk query that can use optional field filters to filter the dataset returned. Can be used as a nested workflow to simplify use.

Updated over a week ago

This workflow template enables the execution of a Splunk search query with the added benefit of optional filtering of the results. Ideal for threat hunting and data analysis, it allows users to return specific fields by providing a comma-delimited list, simplifying data management and integration into larger workflows. Its ease of use and configurability make it a valuable tool for teams requiring quick and targeted access to Splunk data.

Optional Triggers

["Nested Workflow","Webhook"]

Use Cases

Threat Hunting

Workflow Breakdown

  1. Provide the search query and optional field filters

  2. Output will be provided once the search job is finishes

Vendors

Utils, Splunk

Workflow Output

Success/Failure

Tips

  • If a static IP address is required for Splunk, use a step-runner to execute the Splunk steps.

Did this answer your question?