<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>rss.livelink.thread@place:occasion</title>
    <link>https://community.splunk.com/t5/Community-Office-Hours/Getting-Data-In-Session-2-Wed-3-29-23/ec-p/636189#M10</link>
    <description>&lt;P&gt;Jamf pro logs are in xml and its difficult to search for something specific. As an example, I tried searching for just a specific app such as chrome and I get every apps installed on all the hosts instead of just the one I searched for. Also, once I select a specific host, I'm no longer able to see the apps installed on it and vice-versa, once I click on apps, I'm no longer able to see the host.&lt;BR /&gt;&lt;BR /&gt;I'd appreciate any help in parsing this and been able to search for just specific things. My goal is to be able to search for specific apps installed per host.&lt;/P&gt;</description>
    <pubDate>Mon, 27 Mar 2023 17:53:10 GMT</pubDate>
    <dc:creator>liqernzq</dc:creator>
    <dc:date>2023-03-27T17:53:10Z</dc:date>
    <item>
      <title>Getting Data In: Session 2 - Wed 3/29/23</title>
      <link>https://community.splunk.com/t5/Community-Office-Hours/Getting-Data-In-Session-2-Wed-3-29-23/ec-p/632084#M2</link>
      <description>&lt;P&gt;&lt;A href="https://splunk.zoom.us/meeting/register/tJwkf-urrj8uGNUspk_yZ6rGY6YJ7Gl0xK7p" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Register here&lt;/STRONG&gt;&lt;/A&gt;&lt;SPAN&gt; and ask questions below this thread for the Community Office Hours session on &lt;/SPAN&gt;&lt;STRONG&gt;Getting Data In (GDI) to Splunk Platform&lt;/STRONG&gt;&lt;SPAN&gt; on &lt;/SPAN&gt;&lt;STRONG&gt;Wed, March 29, 2023 at 1pm PT / 4pm ET.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This is your opportunity to ask technical Splunk experts questions related to your specific GDI challenge or use case, like&lt;/SPAN&gt;&lt;SPAN&gt; how to onboard common data sources (AWS, Azure, Windows, *nix, etc.), using forwarders, apps to get data in, Data Manager (Splunk Cloud Platform), ingest actions, archiving your data, and anything else you’d like to learn!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;There are two 30-minute sessions in this series. You can choose to attend one or both (each session will cover a different set of questions):&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Wednesday, March 15th – 1:00 pm PT / 4:00 pm ET&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Wednesday, March 29th – 1:00 pm PT / 4:00 pm ET&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Please submit your questions below as comments in advance&lt;/STRONG&gt;&lt;SPAN&gt;. You can also head to &lt;/SPAN&gt;&lt;SPAN&gt;the &lt;/SPAN&gt;&lt;A href="https://splunk-usergroups.slack.com/archives/C0FRVF350" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;#office-hours&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt; user Slack channel to ask questions (request access &lt;/SPAN&gt;&lt;A href="http://splk.it/slack" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;here&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;SPAN&gt;. &lt;/SPAN&gt;&lt;STRONG&gt;Pre-submitted questions (with upvotes) will be prioritized&lt;/STRONG&gt;&lt;SPAN&gt;. After that, we will go in order of the questions posted below, then will open the floor up to live Q&amp;amp;A with meeting participants. If there’s a quick answer available, we’ll post as a direct reply.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Look forward to connecting!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jun 2023 21:43:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Community-Office-Hours/Getting-Data-In-Session-2-Wed-3-29-23/ec-p/632084#M2</guid>
      <dc:creator>brwalker_</dc:creator>
      <dc:date>2023-06-26T21:43:48Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Data In: Session 2 - Wed 3/29/23</title>
      <link>https://community.splunk.com/t5/Community-Office-Hours/Getting-Data-In-Session-2-Wed-3-29-23/ec-p/632884#M6</link>
      <description>&lt;P&gt;Hey Everyone!&lt;/P&gt;&lt;P&gt;Drop your questions/comments here for any topics you'd like to see discussed in the Community Office Hours session&amp;nbsp;&lt;EM&gt;(&lt;/EM&gt;&lt;EM&gt;you can also head to&amp;nbsp;the&amp;nbsp;&lt;A href="https://splunk-usergroups.slack.com/archives/C0FRVF350" target="_blank" rel="noopener nofollow noreferrer"&gt;#office-hours&lt;/A&gt;&amp;nbsp;user Slack channel to ask questions and join the discussion - request access&amp;nbsp;&lt;A href="http://splk.it/slack" target="_blank" rel="noopener nofollow noreferrer"&gt;here&lt;/A&gt;).&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2023 22:08:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Community-Office-Hours/Getting-Data-In-Session-2-Wed-3-29-23/ec-p/632884#M6</guid>
      <dc:creator>adepp</dc:creator>
      <dc:date>2023-03-01T22:08:40Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Data In: Session 2 - Wed 3/29/23</title>
      <link>https://community.splunk.com/t5/Community-Office-Hours/Getting-Data-In-Session-2-Wed-3-29-23/ec-p/636189#M10</link>
      <description>&lt;P&gt;Jamf pro logs are in xml and its difficult to search for something specific. As an example, I tried searching for just a specific app such as chrome and I get every apps installed on all the hosts instead of just the one I searched for. Also, once I select a specific host, I'm no longer able to see the apps installed on it and vice-versa, once I click on apps, I'm no longer able to see the host.&lt;BR /&gt;&lt;BR /&gt;I'd appreciate any help in parsing this and been able to search for just specific things. My goal is to be able to search for specific apps installed per host.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2023 17:53:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Community-Office-Hours/Getting-Data-In-Session-2-Wed-3-29-23/ec-p/636189#M10</guid>
      <dc:creator>liqernzq</dc:creator>
      <dc:date>2023-03-27T17:53:10Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Data In: Session 2 - Wed 3/29/23</title>
      <link>https://community.splunk.com/t5/Community-Office-Hours/Getting-Data-In-Session-2-Wed-3-29-23/ec-p/636225#M11</link>
      <description>&lt;P&gt;Hi, I'm interested in building a health-check dashboard in Splunk for a Pega PRPC (java-based) application.&lt;/P&gt;&lt;P&gt;I would want to ingest data with a) SQL queries and b) parsing the JSON returned by a specific REST call ('ping').&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.pega.com/support-doc/pega-ping-service-faqs?#how-get-active-browser-requestor-count" target="_blank"&gt;Pega Ping service FAQs | Support Center&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2023 22:33:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Community-Office-Hours/Getting-Data-In-Session-2-Wed-3-29-23/ec-p/636225#M11</guid>
      <dc:creator>EricSafern</dc:creator>
      <dc:date>2023-03-27T22:33:37Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Data In: Session 2 - Wed 3/29/23</title>
      <link>https://community.splunk.com/t5/Community-Office-Hours/Getting-Data-In-Session-2-Wed-3-29-23/ec-p/636601#M12</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Expert solution:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Download the Splunkbase App&lt;/STRONG&gt;&lt;SPAN&gt; to GDI from SQL DB: &lt;/SPAN&gt;&lt;A href="https://splunkbase.splunk.com/app/2686" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Splunk DB Connect&lt;/SPAN&gt;&lt;/A&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Data can be imported or exported&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Database Lookups &lt;/SPAN&gt;&lt;I&gt;&lt;SPAN&gt;(where I’m matching a key to a bunch of values inside of that database returning extra fields)&lt;/SPAN&gt;&lt;/I&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Follow these Docs: &lt;/STRONG&gt;&lt;SPAN&gt;GDI from a REST API: &lt;/SPAN&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/AdvancedDev/ModInputsScripts" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Modular Input&lt;/SPAN&gt;&lt;/A&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Protip: &lt;/SPAN&gt;&lt;A href="https://docs.splunk.com/Documentation/AddonBuilder/latest/UserGuide/ConfigureDataCollection" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Splunk Add-on Builder&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;If you use the builder, there’s a GUI that helps you take a step by step approach of getting an API and pulling values back from that, which would do some of that coding for you on the backend.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;Thanks!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2023 22:50:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Community-Office-Hours/Getting-Data-In-Session-2-Wed-3-29-23/ec-p/636601#M12</guid>
      <dc:creator>adepp</dc:creator>
      <dc:date>2023-03-29T22:50:58Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Data In: Session 2 - Wed 3/29/23</title>
      <link>https://community.splunk.com/t5/Community-Office-Hours/Getting-Data-In-Session-2-Wed-3-29-23/ec-p/636602#M13</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Expert Solution:&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Use the search command:&amp;nbsp; &lt;/STRONG&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Xmlkv" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;xmlkv&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;This will understand the XML structure, extract that out into key value pairs, which you can then type into a stats command, a time chart, whichever reporting command you want it after that.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;Roughly what your search will look like:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;index=webapp sourcetype=jamfpro | xmlkv | search app=”&amp;lt;app name&amp;gt;” | stats count by host, app&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Another option:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;| xpath “//xx/xxxx()”&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;| rex&amp;nbsp; &lt;/SPAN&gt;&lt;I&gt;&lt;SPAN&gt;← Just remember to anchor extractions and minimize wildcards for performance reasons&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Another tip: check out this&lt;/STRONG&gt; &lt;/SPAN&gt;&lt;A href="https://medium.com/splunk-engineering/throughput-of-splunk-ingest-actions-with-regular-expressions-best-practices-eff808ca9913" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;great related article&lt;/STRONG&gt;&lt;/A&gt;&lt;SPAN&gt; by Splunker Brent Davis. T&lt;/SPAN&gt;&lt;SPAN&gt;his refers to Ingest Actions but generally a good regex perf article&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are a few more tips that the experts covered in the session (I'll send that slide deck out shortly)!&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2023 22:56:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Community-Office-Hours/Getting-Data-In-Session-2-Wed-3-29-23/ec-p/636602#M13</guid>
      <dc:creator>adepp</dc:creator>
      <dc:date>2023-03-29T22:56:02Z</dc:date>
    </item>
  </channel>
</rss>

