All Apps and Add-ons

Issue with OMS JSON Query

eskarthi
New Member

Hello,

Nowadays we are relaying on OMS query for pulling data into Splunk, however i have noticed some gaps in the OMS - Json query.

For example : we are querying azure activity for every hour and we got some intermittent network disconnection/timeout error for sometime. Once the network connection was resumed the oms connector is not pulling the data from where it left .

Technically the script is constructing values in end,start parameters for extracting the query, however OMS/Log Analytics is not listening to the value we set in end,top,start parameters, it takes only the "query" parameter and execute.

{"query": "AzureActivity | where TimeGenerated > ago(1h)", "end": "2019-05-01T00:00:00", "top": "1", "start": "2019-05-01T11:21:56"}

Furthermore, I have tested the above query using postman utility and the OMS is ignoring those values and i don't know why we are sending those values to Azure ?

is there any way to fix the intermittent connection issues in code ? Please advise.

Thanks
Karthik

0 Karma

jkat54
SplunkTrust
SplunkTrust

The app is a concept app based on the original OMS query language. The API the app used has been changed significantly.

If you can suggest any edits to code, I'd love to make patches for you and the community when I can.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...