<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: combine result foreach in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/combine-result-foreach/m-p/561051#M159471</link>
    <description>&lt;P&gt;You can try ton import this log to test&lt;/P&gt;&lt;LI-CODE lang="c"&gt;Jul 27 17:40:22 myserver tag_audit_log: type=EXECVE msg=audit(1627400420.972:3224562): argc=2 a0="sleep" a1="60"
Jul 27 17:40:22 myserver tag_audit_log: type=EXECVE msg=audit(1627400420.969:3224561): argc=2 a0="awk" a1=7B2073756D202B3D202431207D3B20454E44207B207072696E7420302B73756D207D
Jul 27 17:40:22 myserver tag_audit_log: type=EXECVE msg=audit(1627400420.959:3224560): argc=5 a0="pgrep" a1="-d" a2=20 a3="--" a4="^qemu(-kvm|:.{1,11})$"
Jul 27 17:40:22 myserver tag_audit_log: type=EXECVE msg=audit(1627400420.957:3224559): argc=3 a0="awk" a1=2F5E284D656D467265657C427566666572737C436163686564293A2F207B66726565202B3D2024327D3B20454E44207B7072696E7420667265657D a2="/proc/meminfo"
Jul 27 17:40:14 myserver2 tag_audit_log: type=EXECVE msg=audit(1627400406.970:4065704): argc=2 a0="rm" a1=2F6170706C692F687270726F642F66696C652F50415046472F5053424B335754322E43A35051
Jul 27 17:40:14 myserver2 tag_audit_log: type=EXECVE msg=audit(1627400406.969:4065703): argc=2 a0="rm" a1=2F6170706C692F687270726F642F66696C652F50415046472F5053424B3357592E43A35051
Jul 27 17:40:14 myserver2 tag_audit_log: type=EXECVE msg=audit(1627400406.969:4065702): argc=2 a0="rm" a1=2F6170706C692F687270726F642F66696C652F50415046472F50534244494E54572E43A35051
Jul 27 17:40:14 myserver2 tag_audit_log: type=EXECVE msg=audit(1627400406.968:4065701): argc=2 a0="rm" a1=2F6170706C692F687270726F642F66696C652F50415046472F5053424B3357582E43A35051
Jul 27 17:40:04 myserver2 tag_audit_log: type=EXECVE msg=audit(1627400401.903:4065686): argc=2 a0="date" a1="+%Y%m"
Jul 27 17:40:04 myserver2 tag_audit_log: type=EXECVE msg=audit(1627400401.900:4065685): argc=2 a0="date" a1="+%d"
Jul 27 17:40:04 myserver2 tag_audit_log: type=EXECVE msg=audit(1627400401.898:4065684): argc=4 a0="/bin/sh" a1="/usr/lib64/sa/sa1" a2="1" a3="1"
Jul 27 17:40:04 myserver2 tag_audit_log: type=EXECVE msg=audit(1627400401.897:4065683): argc=3 a0="/bin/sh" a1="-c" a2=2F7573722F6C696236342F73612F73613120312031
Jul 27 17:40:02 myserver tag_audit_log: type=EXECVE msg=audit(1627400401.428:3224556): argc=8 a0="/usr/lib64/sa/sadc" a1="-F" a2="-L" a3="-S" a4="DISK" a5="1" a6="1" a7="-"
Jul 27 17:40:02 myserver tag_audit_log: type=EXECVE msg=audit(1627400401.427:3224555): argc=2 a0="date" a1="+%Y%m"
Jul 27 17:40:02 myserver tag_audit_log: type=EXECVE msg=audit(1627400401.426:3224554): argc=2 a0="date" a1="+%d"
Jul 27 17:40:02 myserver tag_audit_log: type=EXECVE msg=audit(1627400401.424:3224553): argc=4 a0="/bin/sh" a1="/usr/lib64/sa/sa1" a2="1" a3="1"
Jul 27 17:40:02 myserver tag_audit_log: type=EXECVE msg=audit(1627400401.423:3224552): argc=3 a0="/bin/sh" a1="-c" a2=2F7573722F6C696236342F73612F73613120312031
Jul 27 17:39:22 myserver tag_audit_log: type=EXECVE msg=audit(1627400360.956:3224546): argc=2 a0="sleep" a1="60"
Jul 27 17:39:22 myserver tag_audit_log: type=EXECVE msg=audit(1627400360.953:3224545): argc=2 a0="awk" a1=7B2073756D202B3D202431207D3B20454E44207B207072696E7420302B73756D207D
Jul 27 17:39:22 myserver tag_audit_log: type=EXECVE msg=audit(1627400360.943:3224544): argc=5 a0="pgrep" a1="-d" a2=20 a3="--" a4="^qemu(-kvm|:.{1,11})$"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 27 Jul 2021 15:46:23 GMT</pubDate>
    <dc:creator>kevin94120</dc:creator>
    <dc:date>2021-07-27T15:46:23Z</dc:date>
    <item>
      <title>combine result foreach</title>
      <link>https://community.splunk.com/t5/Splunk-Search/combine-result-foreach/m-p/561034#M159462</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;I have a auditd search like&amp;nbsp;&lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;type=EXECVE&lt;/SPAN&gt; &lt;SPAN class="t"&gt;msg=audit&lt;/SPAN&gt;(&lt;SPAN class="t"&gt;16&lt;/SPAN&gt;)&lt;SPAN class="t"&gt;:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;a0=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;sendmail&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;a1=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;-&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;t"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I would like one field with any field like a (a0, a1, a2, a3&amp;nbsp; ect..)&lt;/P&gt;&lt;P&gt;I try:&lt;/P&gt;&lt;P&gt;"type=EXECVE msg=audit(16): argc=2 a0="sendmail""&amp;nbsp;&lt;/P&gt;&lt;P&gt;| foreach a* [ eval test = test +&amp;nbsp; '&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;' ]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No result, I need you help please.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jul 2021 14:39:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/combine-result-foreach/m-p/561034#M159462</guid>
      <dc:creator>kevin94120</dc:creator>
      <dc:date>2021-07-27T14:39:17Z</dc:date>
    </item>
    <item>
      <title>Re: combine result foreach</title>
      <link>https://community.splunk.com/t5/Splunk-Search/combine-result-foreach/m-p/561035#M159463</link>
      <description>&lt;P&gt;You could try something like:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| foreach a* [| eval test = if(isnull(test),'&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;',test +  '&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;') ]&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 27 Jul 2021 14:43:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/combine-result-foreach/m-p/561035#M159463</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-07-27T14:43:00Z</dc:date>
    </item>
    <item>
      <title>Re: combine result foreach</title>
      <link>https://community.splunk.com/t5/Splunk-Search/combine-result-foreach/m-p/561037#M159464</link>
      <description>&lt;P&gt;Thank you for your anwser but unfortunately it dosen't work. I havent values for test&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jul 2021 14:47:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/combine-result-foreach/m-p/561037#M159464</guid>
      <dc:creator>kevin94120</dc:creator>
      <dc:date>2021-07-27T14:47:41Z</dc:date>
    </item>
    <item>
      <title>Re: combine result foreach</title>
      <link>https://community.splunk.com/t5/Splunk-Search/combine-result-foreach/m-p/561038#M159465</link>
      <description>&lt;LI-CODE lang="markup"&gt;| makeresults
| eval a0="sendmail", a1="-t"
| foreach a* 
    [| eval test=if(isnull(test),'&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;',test + '&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;')]&lt;/LI-CODE&gt;&lt;P&gt;Perhaps if you share your real events we might be able to work out why your case doesn't work when this example shows that it does work?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jul 2021 14:56:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/combine-result-foreach/m-p/561038#M159465</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-07-27T14:56:04Z</dc:date>
    </item>
    <item>
      <title>Re: combine result foreach</title>
      <link>https://community.splunk.com/t5/Splunk-Search/combine-result-foreach/m-p/561041#M159466</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kevin94120_0-1627398390694.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/15278i64FEC47AF47F197F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="kevin94120_0-1627398390694.png" alt="kevin94120_0-1627398390694.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;My search is :&lt;/P&gt;&lt;P&gt;index=linux sourcetype=auditd type=EXECVE&lt;BR /&gt;| fields - argc&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jul 2021 15:07:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/combine-result-foreach/m-p/561041#M159466</guid>
      <dc:creator>kevin94120</dc:creator>
      <dc:date>2021-07-27T15:07:02Z</dc:date>
    </item>
    <item>
      <title>Re: combine result foreach</title>
      <link>https://community.splunk.com/t5/Splunk-Search/combine-result-foreach/m-p/561042#M159467</link>
      <description>&lt;P&gt;This solution work. Thank you&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jul 2021 15:09:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/combine-result-foreach/m-p/561042#M159467</guid>
      <dc:creator>kevin94120</dc:creator>
      <dc:date>2021-07-27T15:09:13Z</dc:date>
    </item>
    <item>
      <title>Re: combine result foreach</title>
      <link>https://community.splunk.com/t5/Splunk-Search/combine-result-foreach/m-p/561044#M159468</link>
      <description>&lt;P&gt;Think&amp;nbsp;I answered too quickly , for 5 event I have juste one result&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jul 2021 15:16:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/combine-result-foreach/m-p/561044#M159468</guid>
      <dc:creator>kevin94120</dc:creator>
      <dc:date>2021-07-27T15:16:52Z</dc:date>
    </item>
    <item>
      <title>Re: combine result foreach</title>
      <link>https://community.splunk.com/t5/Splunk-Search/combine-result-foreach/m-p/561045#M159469</link>
      <description>&lt;P&gt;Each event should have its own instance of the test field - by the way, you may want to insert space between each field&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| foreach a* [| eval test = if(isnull(test),'&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;',test + " " +  '&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;') ]&lt;/LI-CODE&gt;&lt;P&gt;What else do you have in your search?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jul 2021 15:22:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/combine-result-foreach/m-p/561045#M159469</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-07-27T15:22:08Z</dc:date>
    </item>
    <item>
      <title>Re: combine result foreach</title>
      <link>https://community.splunk.com/t5/Splunk-Search/combine-result-foreach/m-p/561049#M159470</link>
      <description>&lt;P&gt;Sorry for my english...&lt;/P&gt;&lt;P&gt;Maybe I should not use foreach for my search because I would like for x event of type EXEC with the arguments a0 = * a1 = * ect .. which corresponds to a command, concatenate all the arguments to have the complete command&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jul 2021 15:39:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/combine-result-foreach/m-p/561049#M159470</guid>
      <dc:creator>kevin94120</dc:creator>
      <dc:date>2021-07-27T15:39:05Z</dc:date>
    </item>
    <item>
      <title>Re: combine result foreach</title>
      <link>https://community.splunk.com/t5/Splunk-Search/combine-result-foreach/m-p/561051#M159471</link>
      <description>&lt;P&gt;You can try ton import this log to test&lt;/P&gt;&lt;LI-CODE lang="c"&gt;Jul 27 17:40:22 myserver tag_audit_log: type=EXECVE msg=audit(1627400420.972:3224562): argc=2 a0="sleep" a1="60"
Jul 27 17:40:22 myserver tag_audit_log: type=EXECVE msg=audit(1627400420.969:3224561): argc=2 a0="awk" a1=7B2073756D202B3D202431207D3B20454E44207B207072696E7420302B73756D207D
Jul 27 17:40:22 myserver tag_audit_log: type=EXECVE msg=audit(1627400420.959:3224560): argc=5 a0="pgrep" a1="-d" a2=20 a3="--" a4="^qemu(-kvm|:.{1,11})$"
Jul 27 17:40:22 myserver tag_audit_log: type=EXECVE msg=audit(1627400420.957:3224559): argc=3 a0="awk" a1=2F5E284D656D467265657C427566666572737C436163686564293A2F207B66726565202B3D2024327D3B20454E44207B7072696E7420667265657D a2="/proc/meminfo"
Jul 27 17:40:14 myserver2 tag_audit_log: type=EXECVE msg=audit(1627400406.970:4065704): argc=2 a0="rm" a1=2F6170706C692F687270726F642F66696C652F50415046472F5053424B335754322E43A35051
Jul 27 17:40:14 myserver2 tag_audit_log: type=EXECVE msg=audit(1627400406.969:4065703): argc=2 a0="rm" a1=2F6170706C692F687270726F642F66696C652F50415046472F5053424B3357592E43A35051
Jul 27 17:40:14 myserver2 tag_audit_log: type=EXECVE msg=audit(1627400406.969:4065702): argc=2 a0="rm" a1=2F6170706C692F687270726F642F66696C652F50415046472F50534244494E54572E43A35051
Jul 27 17:40:14 myserver2 tag_audit_log: type=EXECVE msg=audit(1627400406.968:4065701): argc=2 a0="rm" a1=2F6170706C692F687270726F642F66696C652F50415046472F5053424B3357582E43A35051
Jul 27 17:40:04 myserver2 tag_audit_log: type=EXECVE msg=audit(1627400401.903:4065686): argc=2 a0="date" a1="+%Y%m"
Jul 27 17:40:04 myserver2 tag_audit_log: type=EXECVE msg=audit(1627400401.900:4065685): argc=2 a0="date" a1="+%d"
Jul 27 17:40:04 myserver2 tag_audit_log: type=EXECVE msg=audit(1627400401.898:4065684): argc=4 a0="/bin/sh" a1="/usr/lib64/sa/sa1" a2="1" a3="1"
Jul 27 17:40:04 myserver2 tag_audit_log: type=EXECVE msg=audit(1627400401.897:4065683): argc=3 a0="/bin/sh" a1="-c" a2=2F7573722F6C696236342F73612F73613120312031
Jul 27 17:40:02 myserver tag_audit_log: type=EXECVE msg=audit(1627400401.428:3224556): argc=8 a0="/usr/lib64/sa/sadc" a1="-F" a2="-L" a3="-S" a4="DISK" a5="1" a6="1" a7="-"
Jul 27 17:40:02 myserver tag_audit_log: type=EXECVE msg=audit(1627400401.427:3224555): argc=2 a0="date" a1="+%Y%m"
Jul 27 17:40:02 myserver tag_audit_log: type=EXECVE msg=audit(1627400401.426:3224554): argc=2 a0="date" a1="+%d"
Jul 27 17:40:02 myserver tag_audit_log: type=EXECVE msg=audit(1627400401.424:3224553): argc=4 a0="/bin/sh" a1="/usr/lib64/sa/sa1" a2="1" a3="1"
Jul 27 17:40:02 myserver tag_audit_log: type=EXECVE msg=audit(1627400401.423:3224552): argc=3 a0="/bin/sh" a1="-c" a2=2F7573722F6C696236342F73612F73613120312031
Jul 27 17:39:22 myserver tag_audit_log: type=EXECVE msg=audit(1627400360.956:3224546): argc=2 a0="sleep" a1="60"
Jul 27 17:39:22 myserver tag_audit_log: type=EXECVE msg=audit(1627400360.953:3224545): argc=2 a0="awk" a1=7B2073756D202B3D202431207D3B20454E44207B207072696E7420302B73756D207D
Jul 27 17:39:22 myserver tag_audit_log: type=EXECVE msg=audit(1627400360.943:3224544): argc=5 a0="pgrep" a1="-d" a2=20 a3="--" a4="^qemu(-kvm|:.{1,11})$"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jul 2021 15:46:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/combine-result-foreach/m-p/561051#M159471</guid>
      <dc:creator>kevin94120</dc:creator>
      <dc:date>2021-07-27T15:46:23Z</dc:date>
    </item>
    <item>
      <title>Re: combine result foreach</title>
      <link>https://community.splunk.com/t5/Splunk-Search/combine-result-foreach/m-p/561056#M159472</link>
      <description>&lt;LI-CODE lang="markup"&gt;| foreach a* 
    [| eval test=if(isnull(test),'&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;',if(isnull(&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;),test,test + " " + '&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;')) ]&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 27 Jul 2021 16:59:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/combine-result-foreach/m-p/561056#M159472</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-07-27T16:59:02Z</dc:date>
    </item>
    <item>
      <title>Re: combine result foreach</title>
      <link>https://community.splunk.com/t5/Splunk-Search/combine-result-foreach/m-p/561153#M159495</link>
      <description>&lt;P&gt;Perfect!!&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":ok_hand:"&gt;👌&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":folded_hands:"&gt;🙏&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jul 2021 07:38:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/combine-result-foreach/m-p/561153#M159495</guid>
      <dc:creator>kevin94120</dc:creator>
      <dc:date>2021-07-28T07:38:18Z</dc:date>
    </item>
  </channel>
</rss>

