Splunk Enterprise Security

Submit and Extract xml data

avivz
New Member

Hi, I submitted a xml string to specific index using (.submit()) in python.

 index = splunk_client.indexes[index_name]
 index.submit(attack, source=source, sourcetype=uuid, **params)

Then,I tried to extract the data using

kwargs_oneshot = {"count": 0}
query = r"search index="stream_buffer""
    try:

        oneshotsearch_results = splunk_client.jobs.oneshot(query, **kwargs_oneshot)
        query_results = results.ResultsReader(oneshotsearch_results)
        results_list = [result for result in query_results]
    except (ValueError, HTTPError):
        pass
    return results_list

A 166 elements list returned -with the uploaded data- but not in the correct order - so I can't use the returned data.
How can I get the result in the correct order?

0 Karma
Get Updates on the Splunk Community!

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

Register Join this Tech Talk to learn how unique features like Service Centric Views, Tag Spotlight, and ...

Thank You for Celebrating CX Day with Splunk!

Yesterday the entire team at Splunk + Cisco joined the global celebration of CX Day - celebrating our ...