Getting Data In

Databricks to Splunk (Error to load up job results from Databricks to Splunk)

lucasdantascc
New Member

Hi Guys , 

 

I have a query running in this job ID on databricks:

new_job.jpg

 

And , everytime when I try to transport these 5 rows from Databricks into Splunk running in this job 18363943 , it only returns just 1 one row at all:

SPL to transport data from Databricks:

| databricksjob job_id="18363943"
| eval event_name = "Fraude - risco na selfie", severity="High", source = "DataBricks", jira_update_comment = " "
| table-result  event_name , severity, consumer_id,biometric_origin,score, source, jira_update_comment

Results with only one row:

image (2).png

Could you guys help me with this solution or show me where I'm making mistakes writting the code?

I need a script that returns these 5 rows.

Thanks for advance.

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...