- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Team,
Could you please help me on running query in Splunk,
The query starts with | ldapsearch.
run query only have command search,tstats,eval,savedsearch,stats
Could you please guide me on this
Thanks in advance
Regards,
Harisha
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

@harishlnu just leave the command field empty and put the full SPL in the query field and it will work. It may complain about the command field not being populated but IMO that was a silly addition to the app action.
-- Hope this helps! If it does please mark as a solution for the future. Happy SOARing! --
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

@harishlnu just leave the command field empty and put the full SPL in the query field and it will work. It may complain about the command field not being populated but IMO that was a silly addition to the app action.
-- Hope this helps! If it does please mark as a solution for the future. Happy SOARing! --
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It worked Thank you @phanTom
