<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need Help with Splunk Query in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Need-Help-with-Splunk-Query/m-p/602810#M209827</link>
    <description>&lt;P&gt;Sigh. The problem with this solution is that the flow log JSON events can be massive (&amp;gt;500K) and spath /mvexpand can't handle it.&amp;nbsp; Also the best way to use this data would be for each individual flow log entry to have all associated data (Rule included).&amp;nbsp; There are some other techniques discussed in this 2020 blog post that use an Azure Function to send HEC events.&amp;nbsp;&lt;A href="https://www.splunk.com/en_us/blog/platform/splunking-azure-nsg-flow-logs.html" target="_blank"&gt;https://www.splunk.com/en_us/blog/platform/splunking-azure-nsg-flow-logs.html&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 22 Jun 2022 14:11:20 GMT</pubDate>
    <dc:creator>andygerberkp</dc:creator>
    <dc:date>2022-06-22T14:11:20Z</dc:date>
    <item>
      <title>Need Help with Splunk Query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-Help-with-Splunk-Query/m-p/572296#M199460</link>
      <description>&lt;P&gt;Hello Splunkers,&lt;BR /&gt;&lt;BR /&gt;I need help with&amp;nbsp;Network Security Group flow logs where&amp;nbsp; each of the tuples should be a single event &amp;nbsp;with other relevant data for an event.&lt;/P&gt;&lt;P&gt;Sample.log&lt;BR /&gt;&lt;BR /&gt;_raw:&lt;BR /&gt;{"time":"2021-10-25T16:17:50.8670851Z","systemId":"1c5751f4-8686-4ea5-82ee-173b64d401dd","macAddress":"xxxxxxxxxx","category":"NetworkSecurityGroupFlowEvent","resourceId":"/SUBSCRIPTIONS/A80612A2-33D6-47FF-817A-283E8BC8EDD2/RESOURCEGROUPS/C-SAP-EUS-NONPROD-01-INT-NETWORKING-RG/PROVIDERS/MICROSOFT.NETWORK/NETWORKSECURITYGROUPS/DATA-INT-SUBNET-NSG","operationName":"NetworkSecurityGroupFlowEvents","properties":{"Version":2,"flows":[{"rule":"DefaultRule_AllowVnetOutBound","flows":[{"mac":"000D3A57248C","flowTuples":["1635178607,,10.123.2.28,46058,9997,T,O,A,E,1,74,1,60","1635178607,10.115.34.31,10.123.2.18,29128,9997,T,O,A,E,19,7292,16,1227","1635178609,10.115.34.31,10.119.241.5,26540,9997,T,O,A,E,47,54806,64,4395","1635178612,10.115.34.31,13.69.239.72,56024,443,T,O,A,B,,,,","1635178613,10.115.34.31,13.69.239.72,56026,443,T,O,A,B,,,,","1635178614,10.115.34.31,10.192.124.221,56488,80,T,O,A,B,,,,","1635178618,10.115.34.31,13.69.239.72,56024,443,T,O,A,E,8,1158,8,4897"]}]},{"rule":"UserRule_AzAppSubnet_access_toAzDBSubnet_Catch-all","flows":[{"mac":"000D3A57248C","flowTuples":["1635178635,10.115.32.28,10.115.34.31,54322,33015,T,I,A,B,,,,"]}]}]}}&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Json format&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;category&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;NetworkSecurityGroupFlowEvent&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;macAddress&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;xxxxxxxxxx&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;operationName&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;NetworkSecurityGroupFlowEvents&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;properties&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;{&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://es-hal.splunkcloud.com/en-US/app/search/search?q=search%20index%3Derp_azure%0Asourcetype%3D%22mscs%3Ansg%3Aflow%22%0A%7C%20spath%20properties.flows%7B%7D.flows%7B%7D.flowTuples%7B%7D%20output%3Dflows%0A%7C%20mvexpand%20flows&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=standard_perf&amp;amp;earliest=-5m&amp;amp;latest=now&amp;amp;sid=1635172589.46137#" target="_blank" rel="noopener"&gt;[-]&lt;/A&gt;&lt;SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Version&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;2&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;flows&lt;/SPAN&gt;:&amp;nbsp;[&amp;nbsp;&lt;A href="https://es-hal.splunkcloud.com/en-US/app/search/search?q=search%20index%3Derp_azure%0Asourcetype%3D%22mscs%3Ansg%3Aflow%22%0A%7C%20spath%20properties.flows%7B%7D.flows%7B%7D.flowTuples%7B%7D%20output%3Dflows%0A%7C%20mvexpand%20flows&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=standard_perf&amp;amp;earliest=-5m&amp;amp;latest=now&amp;amp;sid=1635172589.46137#" target="_blank" rel="noopener"&gt;[-]&lt;/A&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;{&amp;nbsp;&lt;A href="https://es-hal.splunkcloud.com/en-US/app/search/search?q=search%20index%3Derp_azure%0Asourcetype%3D%22mscs%3Ansg%3Aflow%22%0A%7C%20spath%20properties.flows%7B%7D.flows%7B%7D.flowTuples%7B%7D%20output%3Dflows%0A%7C%20mvexpand%20flows&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=standard_perf&amp;amp;earliest=-5m&amp;amp;latest=now&amp;amp;sid=1635172589.46137#" target="_blank" rel="noopener"&gt;[-]&lt;/A&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;flows&lt;/SPAN&gt;:&amp;nbsp;[&amp;nbsp;&lt;A href="https://es-hal.splunkcloud.com/en-US/app/search/search?q=search%20index%3Derp_azure%0Asourcetype%3D%22mscs%3Ansg%3Aflow%22%0A%7C%20spath%20properties.flows%7B%7D.flows%7B%7D.flowTuples%7B%7D%20output%3Dflows%0A%7C%20mvexpand%20flows&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=standard_perf&amp;amp;earliest=-5m&amp;amp;latest=now&amp;amp;sid=1635172589.46137#" target="_blank" rel="noopener"&gt;[-]&lt;/A&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;{&amp;nbsp;&lt;A href="https://es-hal.splunkcloud.com/en-US/app/search/search?q=search%20index%3Derp_azure%0Asourcetype%3D%22mscs%3Ansg%3Aflow%22%0A%7C%20spath%20properties.flows%7B%7D.flows%7B%7D.flowTuples%7B%7D%20output%3Dflows%0A%7C%20mvexpand%20flows&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=standard_perf&amp;amp;earliest=-5m&amp;amp;latest=now&amp;amp;sid=1635172589.46137#" target="_blank" rel="noopener"&gt;[-]&lt;/A&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;flowTuples&lt;/SPAN&gt;:&amp;nbsp;[&amp;nbsp;&lt;A href="https://es-hal.splunkcloud.com/en-US/app/search/search?q=search%20index%3Derp_azure%0Asourcetype%3D%22mscs%3Ansg%3Aflow%22%0A%7C%20spath%20properties.flows%7B%7D.flows%7B%7D.flowTuples%7B%7D%20output%3Dflows%0A%7C%20mvexpand%20flows&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=standard_perf&amp;amp;earliest=-5m&amp;amp;latest=now&amp;amp;sid=1635172589.46137#" target="_blank" rel="noopener"&gt;[-]&lt;/A&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;1635172376,ip1,ip2,58636,443,T,O,A,E,6,1611,1,66&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;1635172377,ip1,ip2,27910,443,T,O,A,B,,,,&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;1635172377,ip1,ip2,59136,443,T,O,A,E,0,0,0,0&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;1635172378,ip1,ip2,56756,9997,T,O,A,B,,,,&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;1635172378,ip1,ip2,58686,9997,T,O,A,B,,,,&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;1635172379,ip1,ip2,53684,9997,T,O,A,B,,,,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Result:&lt;BR /&gt;Event 1:&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;category&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;NetworkSecurityGroupFlowEvent&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;macAddress&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;xxxxxxxxxx&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;operationName&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;NetworkSecurityGroupFlowEvents&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;properties&lt;/SPAN&gt;:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;{&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://es-hal.splunkcloud.com/en-US/app/search/search?q=search%20index%3Derp_azure%0Asourcetype%3D%22mscs%3Ansg%3Aflow%22%0A%7C%20spath%20properties.flows%7B%7D.flows%7B%7D.flowTuples%7B%7D%20output%3Dflows%0A%7C%20mvexpand%20flows&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=standard_perf&amp;amp;earliest=-5m&amp;amp;latest=now&amp;amp;sid=1635172589.46137#" target="_blank" rel="noopener"&gt;[-]&lt;/A&gt;&lt;SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Version&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;2&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;flows&lt;/SPAN&gt;:&amp;nbsp;[&amp;nbsp;&lt;A href="https://es-hal.splunkcloud.com/en-US/app/search/search?q=search%20index%3Derp_azure%0Asourcetype%3D%22mscs%3Ansg%3Aflow%22%0A%7C%20spath%20properties.flows%7B%7D.flows%7B%7D.flowTuples%7B%7D%20output%3Dflows%0A%7C%20mvexpand%20flows&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=standard_perf&amp;amp;earliest=-5m&amp;amp;latest=now&amp;amp;sid=1635172589.46137#" target="_blank" rel="noopener"&gt;[-]&lt;/A&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;{&amp;nbsp;&lt;A href="https://es-hal.splunkcloud.com/en-US/app/search/search?q=search%20index%3Derp_azure%0Asourcetype%3D%22mscs%3Ansg%3Aflow%22%0A%7C%20spath%20properties.flows%7B%7D.flows%7B%7D.flowTuples%7B%7D%20output%3Dflows%0A%7C%20mvexpand%20flows&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=standard_perf&amp;amp;earliest=-5m&amp;amp;latest=now&amp;amp;sid=1635172589.46137#" target="_blank" rel="noopener"&gt;[-]&lt;/A&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;flows&lt;/SPAN&gt;:&amp;nbsp;[&amp;nbsp;&lt;A href="https://es-hal.splunkcloud.com/en-US/app/search/search?q=search%20index%3Derp_azure%0Asourcetype%3D%22mscs%3Ansg%3Aflow%22%0A%7C%20spath%20properties.flows%7B%7D.flows%7B%7D.flowTuples%7B%7D%20output%3Dflows%0A%7C%20mvexpand%20flows&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=standard_perf&amp;amp;earliest=-5m&amp;amp;latest=now&amp;amp;sid=1635172589.46137#" target="_blank" rel="noopener"&gt;[-]&lt;/A&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;{&amp;nbsp;&lt;A href="https://es-hal.splunkcloud.com/en-US/app/search/search?q=search%20index%3Derp_azure%0Asourcetype%3D%22mscs%3Ansg%3Aflow%22%0A%7C%20spath%20properties.flows%7B%7D.flows%7B%7D.flowTuples%7B%7D%20output%3Dflows%0A%7C%20mvexpand%20flows&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=standard_perf&amp;amp;earliest=-5m&amp;amp;latest=now&amp;amp;sid=1635172589.46137#" target="_blank" rel="noopener"&gt;[-]&lt;/A&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;flowTuples&lt;/SPAN&gt;:&amp;nbsp;[&amp;nbsp;&lt;A href="https://es-hal.splunkcloud.com/en-US/app/search/search?q=search%20index%3Derp_azure%0Asourcetype%3D%22mscs%3Ansg%3Aflow%22%0A%7C%20spath%20properties.flows%7B%7D.flows%7B%7D.flowTuples%7B%7D%20output%3Dflows%0A%7C%20mvexpand%20flows&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=standard_perf&amp;amp;earliest=-5m&amp;amp;latest=now&amp;amp;sid=1635172589.46137#" target="_blank" rel="noopener"&gt;[-]&lt;/A&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;1635172376,ip1,ip2,58636,443,T,O,A,E,6,1611,1,66&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;BR /&gt;Event2:&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN class=""&gt;category&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;NetworkSecurityGroupFlowEvent&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;macAddress&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;xxxxxxxxxx&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;operationName&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;NetworkSecurityGroupFlowEvents&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;properties&lt;/SPAN&gt;:&amp;nbsp;{&amp;nbsp;&lt;A href="https://es-hal.splunkcloud.com/en-US/app/search/search?q=search%20index%3Derp_azure%0Asourcetype%3D%22mscs%3Ansg%3Aflow%22%0A%7C%20spath%20properties.flows%7B%7D.flows%7B%7D.flowTuples%7B%7D%20output%3Dflows%0A%7C%20mvexpand%20flows&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=standard_perf&amp;amp;earliest=-5m&amp;amp;latest=now&amp;amp;sid=1635172589.46137#" target="_blank" rel="noopener"&gt;[-]&lt;/A&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;Version&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;2&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;flows&lt;/SPAN&gt;:&amp;nbsp;[&amp;nbsp;&lt;A href="https://es-hal.splunkcloud.com/en-US/app/search/search?q=search%20index%3Derp_azure%0Asourcetype%3D%22mscs%3Ansg%3Aflow%22%0A%7C%20spath%20properties.flows%7B%7D.flows%7B%7D.flowTuples%7B%7D%20output%3Dflows%0A%7C%20mvexpand%20flows&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=standard_perf&amp;amp;earliest=-5m&amp;amp;latest=now&amp;amp;sid=1635172589.46137#" target="_blank" rel="noopener"&gt;[-]&lt;/A&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;{&amp;nbsp;&lt;A href="https://es-hal.splunkcloud.com/en-US/app/search/search?q=search%20index%3Derp_azure%0Asourcetype%3D%22mscs%3Ansg%3Aflow%22%0A%7C%20spath%20properties.flows%7B%7D.flows%7B%7D.flowTuples%7B%7D%20output%3Dflows%0A%7C%20mvexpand%20flows&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=standard_perf&amp;amp;earliest=-5m&amp;amp;latest=now&amp;amp;sid=1635172589.46137#" target="_blank" rel="noopener"&gt;[-]&lt;/A&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;flows&lt;/SPAN&gt;:&amp;nbsp;[&amp;nbsp;&lt;A href="https://es-hal.splunkcloud.com/en-US/app/search/search?q=search%20index%3Derp_azure%0Asourcetype%3D%22mscs%3Ansg%3Aflow%22%0A%7C%20spath%20properties.flows%7B%7D.flows%7B%7D.flowTuples%7B%7D%20output%3Dflows%0A%7C%20mvexpand%20flows&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=standard_perf&amp;amp;earliest=-5m&amp;amp;latest=now&amp;amp;sid=1635172589.46137#" target="_blank" rel="noopener"&gt;[-]&lt;/A&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;{&amp;nbsp;&lt;A href="https://es-hal.splunkcloud.com/en-US/app/search/search?q=search%20index%3Derp_azure%0Asourcetype%3D%22mscs%3Ansg%3Aflow%22%0A%7C%20spath%20properties.flows%7B%7D.flows%7B%7D.flowTuples%7B%7D%20output%3Dflows%0A%7C%20mvexpand%20flows&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=standard_perf&amp;amp;earliest=-5m&amp;amp;latest=now&amp;amp;sid=1635172589.46137#" target="_blank" rel="noopener"&gt;[-]&lt;/A&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;flowTuples&lt;/SPAN&gt;:&amp;nbsp;[&amp;nbsp;&lt;A href="https://es-hal.splunkcloud.com/en-US/app/search/search?q=search%20index%3Derp_azure%0Asourcetype%3D%22mscs%3Ansg%3Aflow%22%0A%7C%20spath%20properties.flows%7B%7D.flows%7B%7D.flowTuples%7B%7D%20output%3Dflows%0A%7C%20mvexpand%20flows&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=standard_perf&amp;amp;earliest=-5m&amp;amp;latest=now&amp;amp;sid=1635172589.46137#" target="_blank" rel="noopener"&gt;[-]&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;1635172377,ip1,ip2,27910,443,T,O,A,B,,,,&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Thanks&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Oct 2021 16:46:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-Help-with-Splunk-Query/m-p/572296#M199460</guid>
      <dc:creator>nilbak88</dc:creator>
      <dc:date>2021-10-25T16:46:15Z</dc:date>
    </item>
    <item>
      <title>Re: Need Help with Splunk Query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-Help-with-Splunk-Query/m-p/572383#M199489</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/163905"&gt;@harsmarvania57&lt;/a&gt;&amp;nbsp; &amp;nbsp;Can you suggest and help, please ?&lt;/P&gt;</description>
      <pubDate>Tue, 26 Oct 2021 07:27:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-Help-with-Splunk-Query/m-p/572383#M199489</guid>
      <dc:creator>nilbak88</dc:creator>
      <dc:date>2021-10-26T07:27:27Z</dc:date>
    </item>
    <item>
      <title>Re: Need Help with Splunk Query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-Help-with-Splunk-Query/m-p/572403#M199498</link>
      <description>&lt;P&gt;Try something along these lines:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults
| eval _raw="{\"time\":\"2021-10-25T16:17:50.8670851Z\",\"systemId\":\"1c5751f4-8686-4ea5-82ee-173b64d401dd\",\"macAddress\":\"xxxxxxxxxx\",\"category\":\"NetworkSecurityGroupFlowEvent\",\"resourceId\":\"/SUBSCRIPTIONS/A80612A2-33D6-47FF-817A-283E8BC8EDD2/RESOURCEGROUPS/C-SAP-EUS-NONPROD-01-INT-NETWORKING-RG/PROVIDERS/MICROSOFT.NETWORK/NETWORKSECURITYGROUPS/DATA-INT-SUBNET-NSG\",\"operationName\":\"NetworkSecurityGroupFlowEvents\",\"properties\":{\"Version\":2,\"flows\":[{\"rule\":\"DefaultRule_AllowVnetOutBound\",\"flows\":[{\"mac\":\"000D3A57248C\",\"flowTuples\":[\"1635178607,,10.123.2.28,46058,9997,T,O,A,E,1,74,1,60\",\"1635178607,10.115.34.31,10.123.2.18,29128,9997,T,O,A,E,19,7292,16,1227\",\"1635178609,10.115.34.31,10.119.241.5,26540,9997,T,O,A,E,47,54806,64,4395\",\"1635178612,10.115.34.31,13.69.239.72,56024,443,T,O,A,B,,,,\",\"1635178613,10.115.34.31,13.69.239.72,56026,443,T,O,A,B,,,,\",\"1635178614,10.115.34.31,10.192.124.221,56488,80,T,O,A,B,,,,\",\"1635178618,10.115.34.31,13.69.239.72,56024,443,T,O,A,E,8,1158,8,4897\"]}]},{\"rule\":\"UserRule_AzAppSubnet_access_toAzDBSubnet_Catch-all\",\"flows\":[{\"mac\":\"000D3A57248C\",\"flowTuples\":[\"1635178635,10.115.32.28,10.115.34.31,54322,33015,T,I,A,B,,,,\"]}]}]}}"



| spath output=properties.flows properties.flows{}
| mvexpand properties.flows
| spath output=flowTuples properties.flows{}.flows{}.flowTuples{}
| mvexpand flowTuples&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 26 Oct 2021 09:32:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-Help-with-Splunk-Query/m-p/572403#M199498</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-10-26T09:32:26Z</dc:date>
    </item>
    <item>
      <title>Re: Need Help with Splunk Query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-Help-with-Splunk-Query/m-p/572411#M199500</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;Thanks for looking into it.&lt;BR /&gt;I tried with the above suggestion but not getting the desired result.&lt;BR /&gt;&lt;BR /&gt;Here, I want to&amp;nbsp; keep all of the event details and separate the tuples into events.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Oct 2021 09:59:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-Help-with-Splunk-Query/m-p/572411#M199500</guid>
      <dc:creator>nilbak88</dc:creator>
      <dc:date>2021-10-26T09:59:25Z</dc:date>
    </item>
    <item>
      <title>Re: Need Help with Splunk Query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-Help-with-Splunk-Query/m-p/572445#M199515</link>
      <description>&lt;P&gt;All the tuples are separate events - each event has the raw data so you can extract the additional information that you need (with separate spath commands if you need to) - if I were you I would decide exactly which pieces of data you want associated with each tuple and just extract that - alternatively, you could extract everything and prune afterwards.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Oct 2021 12:55:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-Help-with-Splunk-Query/m-p/572445#M199515</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-10-26T12:55:59Z</dc:date>
    </item>
    <item>
      <title>Re: Need Help with Splunk Query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-Help-with-Splunk-Query/m-p/572654#M199591</link>
      <description>&lt;P&gt;Yes, that is the only way I also think so.&lt;BR /&gt;Anyways thanks for all the help&lt;/P&gt;</description>
      <pubDate>Wed, 27 Oct 2021 14:07:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-Help-with-Splunk-Query/m-p/572654#M199591</guid>
      <dc:creator>nilbak88</dc:creator>
      <dc:date>2021-10-27T14:07:06Z</dc:date>
    </item>
    <item>
      <title>Re: Need Help with Splunk Query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-Help-with-Splunk-Query/m-p/602810#M209827</link>
      <description>&lt;P&gt;Sigh. The problem with this solution is that the flow log JSON events can be massive (&amp;gt;500K) and spath /mvexpand can't handle it.&amp;nbsp; Also the best way to use this data would be for each individual flow log entry to have all associated data (Rule included).&amp;nbsp; There are some other techniques discussed in this 2020 blog post that use an Azure Function to send HEC events.&amp;nbsp;&lt;A href="https://www.splunk.com/en_us/blog/platform/splunking-azure-nsg-flow-logs.html" target="_blank"&gt;https://www.splunk.com/en_us/blog/platform/splunking-azure-nsg-flow-logs.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2022 14:11:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-Help-with-Splunk-Query/m-p/602810#M209827</guid>
      <dc:creator>andygerberkp</dc:creator>
      <dc:date>2022-06-22T14:11:20Z</dc:date>
    </item>
  </channel>
</rss>

