Splunk Search

Test Splunk Queries

reesmanp
New Member

I am building a Splunk app for school and one of my requirements is to test that the queries sent to splunk work and are accurate. Is there a way to use unit testing on the queries themselves or should I just make a python script to parse the log files for the data that the query is supposed to gather and compare/contrast?

Tags (2)
0 Karma

michalsvorc
New Member

Sorry for necrobumping, but this thread has over 1K views and still no satisfactory answer. I wonder if someone did find some tool or could share how he resolved this issue.

Would be greatly appreciated by the whole community...

0 Karma

tbroberg
New Member
0 Karma

markthompson
Builder

I am not aware of one - if you can find one, please share.

You could always set up a test index and run it... But if not, your python script should do the trick

0 Karma

reesmanp
New Member

Thanks for that. I will see what I can find and let you know if I did find anything or just used a script.

0 Karma
Get Updates on the Splunk Community!

See Splunk Platform & Observability Innovations at Cisco Live EMEA

Hi Splunkers, Learn about what’s next for Splunk Platform at Cisco Live EMEA.  Data silos are a big challenge ...

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...