Splunk Search

Run Splunk query through excel

splunk_learner_
New Member

I am new to Splunk and still learning..

I have more than 100 queries to run when asked during a daily activity and its a pain to copy and do a paste each and every time asked to run by the team for some kind of validation..

Is there any way I can simply run them through excel like a click on query [ by making it as link ] and it simply deploy splunk in browser and run the query? Or any other option to serve the purpose ?

any help would be appreciated..

Thanks...

Tags (1)
0 Karma

markthomsen
Engager

Maybe this can be done using lookups and the API. You'd load your spreadsheet as a lookup, then use API calls to read that lookup and execute each record (SPL Query) in your spreadsheet. Now that I think about it, you'd have to create a bash or python script to do this, I think.

0 Karma

jpalacian
Path Finder

I'd answer the same like skoelpin, maybe I can add that you can save your queries as reports and your users can access them whenever they need.

0 Karma

skoelpin
SplunkTrust
SplunkTrust

Sounds like a dashboard with multiple panels would be a better option. Also consider scheduled searches which can email results or trigger another action.

Get Updates on the Splunk Community!

Thanks for the Memories! Splunk University, .conf24, and Community Connections

Thank you to everyone in the Splunk Community who joined us for .conf24 – starting with Splunk University and ...

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...