<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Add word in the workflow action. in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Add-word-in-the-workflow-action/m-p/159244#M185906</link>
    <description>&lt;P&gt;Hey yAlff, &lt;/P&gt;

&lt;P&gt;my splunk search returns results without any word with Trend Micro. I want add "Trend Micro + results in my index" in search google. &lt;/P&gt;

&lt;P&gt;For example &lt;/P&gt;

&lt;P&gt;host=ddi| stats count by Reason&lt;/P&gt;

&lt;P&gt;Reason                                           count&lt;BR /&gt;
DNS response resolves to dead IP address     55&lt;BR /&gt;
Many failed log in attempts  1&lt;BR /&gt;
Multiple failed log in attempts   1&lt;/P&gt;

&lt;P&gt;I want search in the google:&lt;/P&gt;

&lt;P&gt;Trend Micro + "DNS response resolves to dead IP address"&lt;/P&gt;

&lt;P&gt;I tried trend micro + $reason and others ways but not happens. In the search goes only Trend Micro.&lt;/P&gt;

&lt;P&gt;any idea ?&lt;/P&gt;

&lt;P&gt;Tks!&lt;/P&gt;</description>
    <pubDate>Thu, 28 Nov 2013 11:28:31 GMT</pubDate>
    <dc:creator>dfigurello</dc:creator>
    <dc:date>2013-11-28T11:28:31Z</dc:date>
    <item>
      <title>Add word in the workflow action.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Add-word-in-the-workflow-action/m-p/159242#M185904</link>
      <description>&lt;P&gt;Hey splunkers, &lt;/P&gt;

&lt;P&gt;I have a doubt. I created a GET workflow action to search field in the google, but I can't put a word before the variable. &lt;/P&gt;

&lt;P&gt;For example:&lt;/P&gt;

&lt;P&gt;(...)google.com/search?$Reason$  it's ok. But I want always search "Trend Micro $Reason". I need add always the word "Trend Micro" for each search with variable $reason, but I can't do it. &lt;/P&gt;

&lt;P&gt;Splunkers any idea?&lt;/P&gt;

&lt;P&gt;Tks.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Nov 2013 00:41:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Add-word-in-the-workflow-action/m-p/159242#M185904</guid>
      <dc:creator>dfigurello</dc:creator>
      <dc:date>2013-11-28T00:41:35Z</dc:date>
    </item>
    <item>
      <title>Re: Add word in the workflow action.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Add-word-in-the-workflow-action/m-p/159243#M185905</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;

&lt;P&gt;did you just try to filter for Trend Micro?&lt;/P&gt;

&lt;P&gt;Just extract the field behind &lt;CODE&gt;search?&lt;/CODE&gt; (maybe named as &lt;CODE&gt;what&lt;/CODE&gt;), and then filter with &lt;CODE&gt;sourcetype=bla what="Trend Micro*"&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;It means that all the returned results contain Trend Micro $reason$ and the just extract the $reason$-tag&lt;/P&gt;

&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Thu, 28 Nov 2013 11:00:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Add-word-in-the-workflow-action/m-p/159243#M185905</guid>
      <dc:creator>yAlff</dc:creator>
      <dc:date>2013-11-28T11:00:57Z</dc:date>
    </item>
    <item>
      <title>Re: Add word in the workflow action.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Add-word-in-the-workflow-action/m-p/159244#M185906</link>
      <description>&lt;P&gt;Hey yAlff, &lt;/P&gt;

&lt;P&gt;my splunk search returns results without any word with Trend Micro. I want add "Trend Micro + results in my index" in search google. &lt;/P&gt;

&lt;P&gt;For example &lt;/P&gt;

&lt;P&gt;host=ddi| stats count by Reason&lt;/P&gt;

&lt;P&gt;Reason                                           count&lt;BR /&gt;
DNS response resolves to dead IP address     55&lt;BR /&gt;
Many failed log in attempts  1&lt;BR /&gt;
Multiple failed log in attempts   1&lt;/P&gt;

&lt;P&gt;I want search in the google:&lt;/P&gt;

&lt;P&gt;Trend Micro + "DNS response resolves to dead IP address"&lt;/P&gt;

&lt;P&gt;I tried trend micro + $reason and others ways but not happens. In the search goes only Trend Micro.&lt;/P&gt;

&lt;P&gt;any idea ?&lt;/P&gt;

&lt;P&gt;Tks!&lt;/P&gt;</description>
      <pubDate>Thu, 28 Nov 2013 11:28:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Add-word-in-the-workflow-action/m-p/159244#M185906</guid>
      <dc:creator>dfigurello</dc:creator>
      <dc:date>2013-11-28T11:28:31Z</dc:date>
    </item>
  </channel>
</rss>

