<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SPLUNk SOAR- Splunk Run query in Splunk SOAR</title>
    <link>https://community.splunk.com/t5/Splunk-SOAR/SPLUNk-SOAR-Splunk-Run-query/m-p/685490#M1489</link>
    <description>&lt;P&gt;Hi Team,&lt;BR /&gt;&lt;BR /&gt;Could you please help me on running query in Splunk,&lt;BR /&gt;The query starts with | ldapsearch.&lt;/P&gt;&lt;P&gt;run query only have command search,tstats,eval,savedsearch,stats&lt;/P&gt;&lt;P&gt;Could you please guide me on this&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Harisha&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 25 Apr 2024 15:09:34 GMT</pubDate>
    <dc:creator>harishlnu</dc:creator>
    <dc:date>2024-04-25T15:09:34Z</dc:date>
    <item>
      <title>SPLUNk SOAR- Splunk Run query</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/SPLUNk-SOAR-Splunk-Run-query/m-p/685490#M1489</link>
      <description>&lt;P&gt;Hi Team,&lt;BR /&gt;&lt;BR /&gt;Could you please help me on running query in Splunk,&lt;BR /&gt;The query starts with | ldapsearch.&lt;/P&gt;&lt;P&gt;run query only have command search,tstats,eval,savedsearch,stats&lt;/P&gt;&lt;P&gt;Could you please guide me on this&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Harisha&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Apr 2024 15:09:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/SPLUNk-SOAR-Splunk-Run-query/m-p/685490#M1489</guid>
      <dc:creator>harishlnu</dc:creator>
      <dc:date>2024-04-25T15:09:34Z</dc:date>
    </item>
    <item>
      <title>Re: SPLUNk SOAR- Splunk Run query</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/SPLUNk-SOAR-Splunk-Run-query/m-p/685493#M1490</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/265957"&gt;@harishlnu&lt;/a&gt;&amp;nbsp;just leave the command field empty and put the full SPL in the query field and it will work. It may complain about the command field not being populated but IMO that was a silly addition to the app action.&lt;/P&gt;&lt;P&gt;-- Hope this helps! If it does please mark as a solution for the future. Happy SOARing! --&lt;/P&gt;</description>
      <pubDate>Thu, 25 Apr 2024 15:25:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/SPLUNk-SOAR-Splunk-Run-query/m-p/685493#M1490</guid>
      <dc:creator>phanTom</dc:creator>
      <dc:date>2024-04-25T15:25:21Z</dc:date>
    </item>
    <item>
      <title>Re: SPLUNk SOAR- Splunk Run query</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/SPLUNk-SOAR-Splunk-Run-query/m-p/685496#M1491</link>
      <description>&lt;P&gt;It worked Thank you&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/222170"&gt;@phanTom&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Apr 2024 15:46:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/SPLUNk-SOAR-Splunk-Run-query/m-p/685496#M1491</guid>
      <dc:creator>harishlnu</dc:creator>
      <dc:date>2024-04-25T15:46:43Z</dc:date>
    </item>
  </channel>
</rss>

