<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Infoblox reporting splunk question. in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Infoblox-reporting-splunk-question-How-to-pull-into-first-search/m-p/616309#M214204</link>
    <description>&lt;P&gt;&lt;SPAN&gt;The following is the answer.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;sourcetype=ib:audit index=ib_audit | sort -_time | rename TIMESTAMP as "Timestamp", ADMIN as "Admin", ACTION as "Action", OBJECT_TYPE as "Object Type", OBJECT_NAME as "Object Name", EXEC_STATUS as "Execution Status", MESSAGE as "Message", host as "Member" | search Admin=* Action=Created OR Action=Deleted "Object Type"="IPv4 Network Container" OR "Object Type"="IPv4 Network" |rex "comment\s(?&amp;lt;comment&amp;gt;\w+)\s" | table Admin, Action, "Object Type", "Object Name", comment&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 07 Oct 2022 12:33:52 GMT</pubDate>
    <dc:creator>DDIGuy</dc:creator>
    <dc:date>2022-10-07T12:33:52Z</dc:date>
    <item>
      <title>Infoblox reporting splunk question: How to pull into first search query?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Infoblox-reporting-splunk-question-How-to-pull-into-first-search/m-p/615659#M213948</link>
      <description>&lt;P&gt;Hi, I'm using the following search string in Infoblox reporting:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;sourcetype=ib:audit index=ib_audit | sort -_time | rename TIMESTAMP as "Timestamp", ADMIN as "Admin", ACTION as "Action", OBJECT_TYPE as "Object Type", OBJECT_NAME as "Object Name", EXEC_STATUS as "Execution Status", MESSAGE as "Message", host as "Member" | search Admin=* Action=Created OR Action=Deleted "Object Type"="IPv4 Network Container" OR "Object Type"="IPv4 Network" | fields + Action, Admin, Member, "Object Name", "Object Type", "Comment" Timestamp |fields - _raw, _time&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This search is to alert on new network or network containers created via the audit log. What I would like to do in addition to this, is pull in the comment from the network, which looks like this from the splunk search:&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN class=""&gt;2022-10-03&lt;/SPAN&gt; &lt;SPAN class=""&gt;15:00:23.984Z&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;SPAN class=""&gt;guestrw&lt;/SPAN&gt;&lt;SPAN&gt;]&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt; &lt;SPAN class=""&gt;Created&lt;/SPAN&gt; &lt;SPAN class=""&gt;Network&lt;/SPAN&gt; &lt;SPAN class=""&gt;192.168.100.0/24&lt;/SPAN&gt; &lt;SPAN class=""&gt;network_view=default&lt;/SPAN&gt; &lt;SPAN class=""&gt;extensible_attributes=&lt;/SPAN&gt;&lt;SPAN&gt;[[&lt;/SPAN&gt;&lt;SPAN class=""&gt;name=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;Building&lt;/SPAN&gt;&lt;SPAN&gt;",&lt;/SPAN&gt;&lt;SPAN class=""&gt;value=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;B2&lt;/SPAN&gt;&lt;SPAN&gt;"]],&lt;/SPAN&gt;&lt;SPAN class=""&gt;address=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;192.168.100.0&lt;/SPAN&gt;&lt;SPAN&gt;",&lt;/SPAN&gt;&lt;SPAN class=""&gt;auto_create_reversezone=False&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;SPAN class=""&gt;cidr=24&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;SPAN class=""&gt;comment=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;DDIguy&lt;/SPAN&gt; &lt;SPAN class=""&gt;Reporting&lt;/SPAN&gt; &lt;SPAN class=""&gt;test&lt;/SPAN&gt;&lt;SPAN&gt;",&lt;/SPAN&gt;&lt;SPAN class=""&gt;common_properties=&lt;/SPAN&gt;&lt;SPAN&gt;[&lt;/SPAN&gt;&lt;SPAN class=""&gt;domain_name_servers=&lt;/SPAN&gt;&lt;SPAN&gt;[],&lt;/SPAN&gt;&lt;SPAN class=""&gt;routers=&lt;/SPAN&gt;&lt;SPAN&gt;[]],&lt;/SPAN&gt;&lt;SPAN class=""&gt;disabled=False&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;SPAN class=""&gt;discovery_member=NULL&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;SPAN class=""&gt;enable_discovery=False&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;SPAN class=""&gt;enable_immediate_discovery=False&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;SPAN class=""&gt;network_view=NetworkView:default&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;SPAN class=""&gt;use_basic_polling_settings=False&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;SPAN class=""&gt;use_member_enable_discovery=False&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;"commentDDIGUY Reporting test"&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Can someone please help me understand how I can pull that into the first search query?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Oct 2022 14:14:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Infoblox-reporting-splunk-question-How-to-pull-into-first-search/m-p/615659#M213948</guid>
      <dc:creator>DDIGuy</dc:creator>
      <dc:date>2022-10-07T14:14:08Z</dc:date>
    </item>
    <item>
      <title>Re: How can I pull report into original search?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Infoblox-reporting-splunk-question-How-to-pull-into-first-search/m-p/615686#M213956</link>
      <description>&lt;P&gt;I'm not sure what you want to achieve in the end. Your search should return some fields and then what? What do you mean by "pull"? You want to search for some other events based on some set of fields returned by this search?&lt;/P&gt;&lt;P&gt;Anyway, get that sort to the end of your pipeline. And just search for the original fields before the rename. Splunk can be sometimes smart and optimize some things but I wouldn't count on that and it's best to be as specific as you can with your search terms.&lt;/P&gt;&lt;P&gt;Also it may be just my personal taste but I don't like counting on the built-in precedence on conditions - adding parentheses helps readability IMHO.&lt;/P&gt;&lt;P&gt;So I'd start with&lt;/P&gt;&lt;PRE&gt;sourcetype=ib:audit index=ib_audit ADMIN=* (ACTION=Created OR ACTION=Deleted) (OBJECT_TYPE="IPv4 Network Container" OR "Object Type"="IPv4 Network")&lt;BR /&gt;| rename TIMESTAMP as "Timestamp", ADMIN as "Admin", ACTION as "Action", OBJECT_TYPE as "Object Type", OBJECT_NAME as "Object Name", EXEC_STATUS as "Execution Status", MESSAGE as "Message", host as "Member"&lt;BR /&gt;| fields + Action, Admin, Member, "Object Name", "Object Type", "Comment" Timestamp &lt;BR /&gt;| fields - _raw, _time&lt;BR /&gt;| sort -_time&lt;/PRE&gt;&lt;P&gt;(I wouldn't sort if I was to do later something that doesn't rely on event order)&lt;/P&gt;&lt;P&gt;And then think what next.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Oct 2022 17:50:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Infoblox-reporting-splunk-question-How-to-pull-into-first-search/m-p/615686#M213956</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-10-03T17:50:57Z</dc:date>
    </item>
    <item>
      <title>Re: Infoblox reporting splunk question.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Infoblox-reporting-splunk-question-How-to-pull-into-first-search/m-p/615687#M213957</link>
      <description>&lt;P&gt;I am generating a report which includes all the networks and network containers created. This is working with the criteria I've provided. However, the "comment" isn't included and I would like it to be.&amp;nbsp; I would like this line to be included in the search "&lt;SPAN class=""&gt;comment=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;DDIguy&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Reporting&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;test&lt;/SPAN&gt;&lt;SPAN&gt;" but can't figure out how to add that into the search criteria.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DDIGuy_0-1664820062238.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/21838iA16155520566FF7C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="DDIGuy_0-1664820062238.png" alt="DDIGuy_0-1664820062238.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I'd like to pull the highlighted bit out of this stock report and include it in the report above ^.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DDIGuy_1-1664820246452.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/21839i0AD8216A8BC1BE20/image-size/medium?v=v2&amp;amp;px=400" role="button" title="DDIGuy_1-1664820246452.png" alt="DDIGuy_1-1664820246452.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Oct 2022 18:04:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Infoblox-reporting-splunk-question-How-to-pull-into-first-search/m-p/615687#M213957</guid>
      <dc:creator>DDIGuy</dc:creator>
      <dc:date>2022-10-03T18:04:12Z</dc:date>
    </item>
    <item>
      <title>Re: Infoblox reporting splunk question.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Infoblox-reporting-splunk-question-How-to-pull-into-first-search/m-p/616309#M214204</link>
      <description>&lt;P&gt;&lt;SPAN&gt;The following is the answer.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;sourcetype=ib:audit index=ib_audit | sort -_time | rename TIMESTAMP as "Timestamp", ADMIN as "Admin", ACTION as "Action", OBJECT_TYPE as "Object Type", OBJECT_NAME as "Object Name", EXEC_STATUS as "Execution Status", MESSAGE as "Message", host as "Member" | search Admin=* Action=Created OR Action=Deleted "Object Type"="IPv4 Network Container" OR "Object Type"="IPv4 Network" |rex "comment\s(?&amp;lt;comment&amp;gt;\w+)\s" | table Admin, Action, "Object Type", "Object Name", comment&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Oct 2022 12:33:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Infoblox-reporting-splunk-question-How-to-pull-into-first-search/m-p/616309#M214204</guid>
      <dc:creator>DDIGuy</dc:creator>
      <dc:date>2022-10-07T12:33:52Z</dc:date>
    </item>
    <item>
      <title>Re: Infoblox reporting splunk question.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Infoblox-reporting-splunk-question-How-to-pull-into-first-search/m-p/616328#M214207</link>
      <description>&lt;P&gt;Three things:&lt;/P&gt;&lt;P&gt;1) As I wrote earlier - order of operations matters. So sorting the data unnecessarily makes the search slower. Especially if you don't need the data sorted. But even if you do, sort it at the end.&lt;/P&gt;&lt;P&gt;2) Don't use table unless you absolutely need to. it would be enough to select a set of fields using &lt;EM&gt;fields&lt;/EM&gt; command. Why am I bringing this up? Because if you decide to extend this search further by appending more commands with &lt;EM&gt;table&lt;/EM&gt; you move the processing to the search heads and you can't take advantage of distributed nature of Splunk environment.&lt;/P&gt;&lt;P&gt;3) For one-off jobs, using rex is perfectly OK, but in general case if the comment field is not extracted, it should be added to extractions for the sourcetype so it can be used easily by anyone and searching on this field can operate efficiently.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Oct 2022 14:40:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Infoblox-reporting-splunk-question-How-to-pull-into-first-search/m-p/616328#M214207</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-10-07T14:40:54Z</dc:date>
    </item>
  </channel>
</rss>

