Splunk Dev

Indexing the results from the running an inspect using the CLI version of splunk-appinspect?

chris_barrett
SplunkTrust
SplunkTrust

Before I go and re-invent the wheel, has anyone looked at indexing the results from the running an inspect using the CLI version of splunk-appinspect?

The --output-file is, by default, JSON and has a start_time field in it which could be used for the event's _time.

And, if you run it with --generate-feedback, then you get a YAML file which can be converted to JSON using the yq command.  The result JSON file also has a start_time field in it which could be used for the event's _time.

As for a use-case... I don't know (yet).  At this stage, it's really just a wouldn't it be cool to ...

Labels (1)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...