<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk table query in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Splunk-table-query/m-p/707083#M239203</link>
    <description>&lt;P&gt;This is one of few occasions that transaction command is appropriate. &amp;nbsp;Something like&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rename "Log text" as LogText
| transaction maxspan=120s startswith="LogText = disconnected" endswith="LogText = connected" keeporphans=true
| where isnull(closed_txn)&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your mock data would give&lt;/P&gt;&lt;TABLE width="677px"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="110px"&gt;LogText&lt;/TD&gt;&lt;TD width="43px"&gt;Row&lt;/TD&gt;&lt;TD width="165.640625px"&gt;_time&lt;/TD&gt;&lt;TD width="67.890625px"&gt;closed_txn&lt;/TD&gt;&lt;TD width="53.953125px"&gt;duration&lt;/TD&gt;&lt;TD width="69.890625px"&gt;eventcount&lt;/TD&gt;&lt;TD width="107.734375px"&gt;field_match_sum&lt;/TD&gt;&lt;TD width="57.9375px"&gt;linecount&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="110px"&gt;disconnected&lt;/TD&gt;&lt;TD width="43px"&gt;5&lt;/TD&gt;&lt;TD width="165.640625px"&gt;2024-12-17 08:10:30&lt;/TD&gt;&lt;TD width="67.890625px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="53.953125px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="69.890625px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="107.734375px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="57.9375px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="110px"&gt;disconnected&lt;/TD&gt;&lt;TD width="43px"&gt;4&lt;/TD&gt;&lt;TD width="165.640625px"&gt;2024-12-17 08:00:10&lt;/TD&gt;&lt;TD width="67.890625px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="53.953125px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="69.890625px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="107.734375px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="57.9375px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;Here is an emulation of your mock data.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults format=csv data="Row,	_time,	Log text
1,	7:00:00am,	connected
2,	7:30:50am,	disconnected
3,	7:31:30am,	connected
4,	8:00:10am,	disconnected
5,	8:10:30am,	disconnected"
| eval _time = strptime(_time, "%I:%M:%S%p")
| sort - _time
``` data emulation above ```&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Play with the emulation and compare with real data.&lt;/P&gt;</description>
    <pubDate>Tue, 17 Dec 2024 22:24:39 GMT</pubDate>
    <dc:creator>yuanliu</dc:creator>
    <dc:date>2024-12-17T22:24:39Z</dc:date>
    <item>
      <title>Splunk table query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-table-query/m-p/707070#M239199</link>
      <description>&lt;P&gt;I've piped a Splunk log query extract into a table showing disconnected and connected log entries sorted by time.&lt;/P&gt;&lt;P&gt;NB row 1 is fine. Row 2 is fine because it connected within 120 sec.&lt;/P&gt;&lt;P&gt;Now I want to show "&lt;STRONG&gt;disconnected&lt;/STRONG&gt;" entries with no subsequent "&lt;STRONG&gt;connected&lt;/STRONG&gt;" row say within a 120 sec time frame.&amp;nbsp; So, I want to pick up rows 4 and 5.&lt;/P&gt;&lt;P&gt;Can someone advise on the Splunk query format for this?&lt;/P&gt;&lt;P&gt;Table = Connect_Log&lt;/P&gt;&lt;TABLE border="1" width="56.25029825310335%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="25%"&gt;&lt;STRONG&gt;Row&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="25%"&gt;&lt;STRONG&gt;Time&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="25%"&gt;&lt;STRONG&gt;Log text&lt;/STRONG&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%"&gt;1&lt;/TD&gt;&lt;TD width="25%"&gt;&lt;FONT color="#008000"&gt;7:00:00am&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="25%"&gt;&lt;FONT color="#008000"&gt;connected&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%"&gt;2&lt;/TD&gt;&lt;TD width="25%"&gt;&lt;FONT color="#008000"&gt;7:30:50am&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="25%"&gt;&lt;FONT color="#008000"&gt;disconnected&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%"&gt;3&lt;/TD&gt;&lt;TD width="25%"&gt;&lt;FONT color="#008000"&gt;7:31:30am&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="25%"&gt;&lt;FONT color="#008000"&gt;connected&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;4&lt;/TD&gt;&lt;TD&gt;&lt;FONT color="#FF0000"&gt;8:00:10am&lt;/FONT&gt;&lt;/TD&gt;&lt;TD&gt;&lt;FONT color="#FF0000"&gt;disconnected&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;5&lt;/TD&gt;&lt;TD&gt;&lt;FONT color="#FF0000"&gt;8:10:30am&lt;/FONT&gt;&lt;/TD&gt;&lt;TD&gt;&lt;FONT color="#FF0000"&gt;disconnected&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Tue, 17 Dec 2024 19:24:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-table-query/m-p/707070#M239199</guid>
      <dc:creator>CCP_tech</dc:creator>
      <dc:date>2024-12-17T19:24:39Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk table query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-table-query/m-p/707083#M239203</link>
      <description>&lt;P&gt;This is one of few occasions that transaction command is appropriate. &amp;nbsp;Something like&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rename "Log text" as LogText
| transaction maxspan=120s startswith="LogText = disconnected" endswith="LogText = connected" keeporphans=true
| where isnull(closed_txn)&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your mock data would give&lt;/P&gt;&lt;TABLE width="677px"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="110px"&gt;LogText&lt;/TD&gt;&lt;TD width="43px"&gt;Row&lt;/TD&gt;&lt;TD width="165.640625px"&gt;_time&lt;/TD&gt;&lt;TD width="67.890625px"&gt;closed_txn&lt;/TD&gt;&lt;TD width="53.953125px"&gt;duration&lt;/TD&gt;&lt;TD width="69.890625px"&gt;eventcount&lt;/TD&gt;&lt;TD width="107.734375px"&gt;field_match_sum&lt;/TD&gt;&lt;TD width="57.9375px"&gt;linecount&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="110px"&gt;disconnected&lt;/TD&gt;&lt;TD width="43px"&gt;5&lt;/TD&gt;&lt;TD width="165.640625px"&gt;2024-12-17 08:10:30&lt;/TD&gt;&lt;TD width="67.890625px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="53.953125px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="69.890625px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="107.734375px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="57.9375px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="110px"&gt;disconnected&lt;/TD&gt;&lt;TD width="43px"&gt;4&lt;/TD&gt;&lt;TD width="165.640625px"&gt;2024-12-17 08:00:10&lt;/TD&gt;&lt;TD width="67.890625px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="53.953125px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="69.890625px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="107.734375px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="57.9375px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;Here is an emulation of your mock data.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults format=csv data="Row,	_time,	Log text
1,	7:00:00am,	connected
2,	7:30:50am,	disconnected
3,	7:31:30am,	connected
4,	8:00:10am,	disconnected
5,	8:10:30am,	disconnected"
| eval _time = strptime(_time, "%I:%M:%S%p")
| sort - _time
``` data emulation above ```&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Play with the emulation and compare with real data.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2024 22:24:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-table-query/m-p/707083#M239203</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2024-12-17T22:24:39Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk table query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-table-query/m-p/707087#M239205</link>
      <description>&lt;P&gt;You can also do it with streamstats with the last two lines of this example - note the field name &lt;STRONG&gt;Log_text&lt;/STRONG&gt;, with the _ in the middle, as the reset_after statement doesn't like spaces in the field name.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults format=csv data="Row,Time,Log_text
1,7:00:00am,connected
2,7:30:50am,disconnected
3,7:31:30am,connected
4,8:00:10am,disconnected
5,8:10:30am,disconnected"
| eval _time=strptime(Time, "%H:%M:%S")
| sort - _time
| streamstats time_window=120s reset_after="("Log_text=\"disconnected\"")" count
| where count=1 AND Log_text="disconnected"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Dec 2024 00:26:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-table-query/m-p/707087#M239205</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2024-12-18T00:26:32Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk table query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-table-query/m-p/707099#M239208</link>
      <description>&lt;P&gt;The overall idea is ok but if you want to check if something happens _after_ an interesting event you must reverse the original data stream because you cannot streamstats backwards. But the example data was in chronological order while the defaul result sorting is opposite. So it's all a bit confusing.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Dec 2024 05:49:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-table-query/m-p/707099#M239208</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-12-18T05:49:34Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk table query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-table-query/m-p/707104#M239212</link>
      <description>&lt;P&gt;Yes, this one works because the connected AFTER the disconnected does not happen, resulting in the count=1 for a disconnect - normally you'd get them in reverse and in this case, that would be the order needed. It rather trivialises the example, but without knowing the data, it's hard to know if it would work in all cases.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Dec 2024 06:38:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-table-query/m-p/707104#M239212</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2024-12-18T06:38:10Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk table query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-table-query/m-p/707109#M239215</link>
      <description>&lt;P&gt;Yes. I'm just pointing it out because it's a common use case - to find something that is (not) followed by another something and it's a bit unintuitive that Splunk by default returns results in reverse chronological order. So you sometimes need to either manipulate the order of results so that "previous" in terms of carrying over values further down the stream means the desired way. Or you have to remember that you're returning the end of some interesting period, not its beginning.&lt;/P&gt;&lt;P&gt;As I said - depending on the use case it can be sometimes confusing and it's worth remembering to always double check your results order when you're doing similar things.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Dec 2024 07:23:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-table-query/m-p/707109#M239215</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-12-18T07:23:46Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk table query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-table-query/m-p/707110#M239216</link>
      <description>&lt;P&gt;Thanks for response. I will try it out.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Dec 2024 07:41:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-table-query/m-p/707110#M239216</guid>
      <dc:creator>CCP_tech</dc:creator>
      <dc:date>2024-12-18T07:41:27Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk table query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-table-query/m-p/707146#M239218</link>
      <description>&lt;P&gt;My bad - The LogText column has the key word (&lt;STRONG&gt;connected&lt;/STRONG&gt; or &lt;STRONG&gt;disconnected&lt;/STRONG&gt;) with other texts. It will some kind of wildcard lookup for either of these 2 words.&lt;/P&gt;&lt;P&gt;So, I'm looking to extract row 4 and 5 which has the "disconnected" text and where there isn't an associated connected row within say 120 secs.&amp;nbsp;&lt;/P&gt;&lt;TABLE border="1" width="56.25029825310335%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="25%"&gt;&lt;STRONG&gt;Row&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="25%"&gt;&lt;STRONG&gt;Time&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="25%"&gt;&lt;STRONG&gt;LogText&lt;/STRONG&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%"&gt;1&lt;/TD&gt;&lt;TD width="25%"&gt;&lt;FONT color="#008000"&gt;7:00:00am&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="25%"&gt;&lt;FONT color="#008000"&gt;text &lt;STRONG&gt;connected&lt;/STRONG&gt; text&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%"&gt;2&lt;/TD&gt;&lt;TD width="25%"&gt;&lt;FONT color="#008000"&gt;7:30:50am&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="25%"&gt;&lt;P&gt;&lt;FONT color="#008000"&gt;text &lt;STRONG&gt;disconnected&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#008000"&gt;text&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%"&gt;3&lt;/TD&gt;&lt;TD width="25%"&gt;&lt;FONT color="#008000"&gt;7:31:30am&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="25%"&gt;&lt;FONT color="#008000"&gt;text &lt;STRONG&gt;connected&lt;/STRONG&gt; text&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;4&lt;/TD&gt;&lt;TD&gt;&lt;FONT color="#FF0000"&gt;8:00:10am&lt;/FONT&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;text &lt;STRONG&gt;disconnected&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;text&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;5&lt;/TD&gt;&lt;TD&gt;&lt;FONT color="#FF0000"&gt;8:10:30am&lt;/FONT&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;text &lt;STRONG&gt;disconnected&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;text&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Wed, 18 Dec 2024 11:53:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-table-query/m-p/707146#M239218</guid>
      <dc:creator>CCP_tech</dc:creator>
      <dc:date>2024-12-18T11:53:57Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk table query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-table-query/m-p/707253#M239234</link>
      <description>&lt;P&gt;Sure. &amp;nbsp;startswith and endwith can also be sophisticated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rename "Log text" as LogText
| transaction maxspan=120s startswith=eval(match(LogText, "\bdisconnected\b")) endswith=eval(match(LogText, "\bconnected\b")) keeporphans=true
| where isnull(closed_txn)&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is an emulation&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults format=csv data="Row,	_time,	Log text
1,	7:00:00am,	text connected\ntext
2,	7:30:50am,	text\ndisconnected\n\ntext
3,	7:31:30am,	text connected\ntext
4,	8:00:10am,	text\ndisconnected\n\ntext
5,	8:10:30am,	text\ndisconnected\n\ntext"
| eval _time = strptime(_time, "%I:%M:%S%p"), "Log text" = replace('Log text', "\\\n", "
")
| sort - _time
``` data emulation above ```&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The above search gives&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;LogText&lt;/TD&gt;&lt;TD&gt;Row&lt;/TD&gt;&lt;TD&gt;_raw&lt;/TD&gt;&lt;TD&gt;_time&lt;/TD&gt;&lt;TD&gt;closed_txn&lt;/TD&gt;&lt;TD&gt;duration&lt;/TD&gt;&lt;TD&gt;eventcount&lt;/TD&gt;&lt;TD&gt;field_match_sum&lt;/TD&gt;&lt;TD&gt;linecount&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;text disconnected text&lt;/TD&gt;&lt;TD&gt;5&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;TD&gt;2024-12-18 08:10:30&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;text disconnected text&lt;/TD&gt;&lt;TD&gt;4&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;TD&gt;2024-12-18 08:00:10&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Thu, 19 Dec 2024 07:23:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-table-query/m-p/707253#M239234</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2024-12-19T07:23:16Z</dc:date>
    </item>
  </channel>
</rss>

