Splunk Search

Test Splunk Queries

reesmanp
New Member

I am building a Splunk app for school and one of my requirements is to test that the queries sent to splunk work and are accurate. Is there a way to use unit testing on the queries themselves or should I just make a python script to parse the log files for the data that the query is supposed to gather and compare/contrast?

Tags (2)
0 Karma

michalsvorc
New Member

Sorry for necrobumping, but this thread has over 1K views and still no satisfactory answer. I wonder if someone did find some tool or could share how he resolved this issue.

Would be greatly appreciated by the whole community...

0 Karma

tbroberg
New Member
0 Karma

markthompson
Builder

I am not aware of one - if you can find one, please share.

You could always set up a test index and run it... But if not, your python script should do the trick

0 Karma

reesmanp
New Member

Thanks for that. I will see what I can find and let you know if I did find anything or just used a script.

0 Karma
Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...