Splunk Search

Why can I not read grouped data from SPLUNK Rest API via ADF?

kilimche
Explorer

Hello,

I am facing an issue while I try reading from Rest API Splunk Aggregated info.

A query that uses the calculation below is able to provide 4 columns via UI but not via ADF Rest API where I get only the Total result. Seems to me like the issue is with the grouped data which can not be read for some reason. Any suggestion please?

| eval Days=(relative_time(now(), "@month+28d")-patchLevelDate)/86400 | where time>relative_time(now(), "-30d") | eval system="2. VDI Persistent" | eval compliant=if(Days<70, "Yes", "No")]
| chart count(host) by system compliant | addtotals 

 

 

Labels (2)
0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...