<h2>Splunk Event Query activity</h2><br/><div style="overflow-x:auto"> <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"><head><meta content="text/html; charset=UTF-8" /><meta name="copyright" content="(C) Copyright 2024" /><meta name="DC.rights.owner" content="(C) Copyright 2024" /><meta name="generator" content="DITA-OT" /><meta name="DC.type" content="reference" /><meta name="DC.title" content="Splunk Event Query activity" /><meta name="abstract" content="The Splunk Event Query workflow activity searches the Splunk event logs for malicious indicators." /><meta name="description" content="The Splunk Event Query workflow activity searches the Splunk event logs for malicious indicators." /><meta name="DC.subject" content="security operations integration workflow activities, splunk event query" /><meta name="keywords" content="security operations integration workflow activities, splunk event query" /><meta name="DC.relation" scheme="URI" content="../../../product/security-operations-integrations/task/secops-integration-sightings-search-splunk-workflow.html" /><meta name="DC.relation" scheme="URI" content="../../../product/security-operations-common/concept/sec-ops-common-functionality.html" /><meta name="DC.relation" scheme="URI" content="../../../product/secops-integration-reference/concept/secops-integ-ref.html" /><meta name="DC.relation" scheme="URI" content="../../../product/security-operations-common/concept/integration-capabilities.html" /><meta name="DC.relation" scheme="URI" content="../../../product/security-operations-common/concept/sightings-search-capability.html" /><meta name="DC.relation" scheme="URI" content="../../../product/security-incident-response/task/sightings-search-configurations.html" /><meta name="DC.relation" scheme="URI" content="../../../product/security-operations-integrations/task/secops-integration-sightings-search-workflow.html" /><meta name="DC.creator" content="Harish Sockalingam" /><meta name="DC.creator" content="Lisa Hultman" /><meta name="DC.creator" content="ServiceNow" /><meta name="DC.date.created" content="2023-08-03" /><meta name="DC.date.modified" content="2024-08-01" /><meta name="DC.format" content="XHTML" /><meta name="DC.identifier" content="event-query-splunk-activity" /><link rel="stylesheet" type="text/css" href="../../../CSS/commonltr.css" /><title>Splunk Event Query activity</title></head><body id="event-query-splunk-activity"> <div class="breadcrumb"><a class="link" href="../../../product/security-operations-common/concept/sec-ops-common-functionality.html" title="Whenever any of the plugins for the main Security Operations applications (Security Incident Response, Vulnerability Response, Threat Intelligence, or Configuration Compliance) are activated, the Security Support Common plugin is activated. This plugin loads various modules that provide functionality that is common across all Security Operations applications.">Security Operations common functionality</a> > <a class="link" href="../../../product/secops-integration-reference/concept/secops-integ-ref.html" title="Developers and ServiceNow partners can use the information in this section to gain understanding of the under-the-hood functionality of third-party integrations, including development guidelines, integration capabilities, and workflows.">Security Operations Integration Reference</a> > <a class="link" href="../../../product/security-operations-common/concept/integration-capabilities.html" title="The Integration Capabilities framework provides a consistent architecture to support interoperability with third-party integrations. This abstracted interface and data model insulates integrations from changes to the core application and ensures a consistent experience for similar types of integrations.">Integration capabilities</a> > <a class="link" href="../../../product/security-operations-common/concept/sightings-search-capability.html" title="The Sightings Search capability accepts a set of observables, finds any integrations that support a Sightings Search, then executes these searches.">Security Operations Integration- Sightings Search capability</a> > <a class="link" href="../../../product/security-incident-response/task/sightings-search-configurations.html" title="Create multiple sightings search configuration records and use them while querying multiple log stores or varying the search parameters.">Create sightings search configuration records</a> > <a class="link" href="../../../product/security-operations-integrations/task/secops-integration-sightings-search-workflow.html" title="Security Operations Integration - Sightings Search workflow is a high-level workflow independent of integrations. It uses the configured queries to search for a set of observables based on the configured integrations which support the capability. Use it to fulfill an integration such as Splunk or Elasticsearch.">Security Operations Integration - Sightings Search workflow</a> > </div> <h1 class="title topictitle1" id="ariaid-title1">Splunk Event Query activity</h1> <div class="body refbody"><p class="shortdesc">The <span class="ph uicontrol">Splunk Event Query</span> workflow activity searches the Splunk event logs for malicious indicators.</p> <div class="section"> <p class="p">The <span class="ph uicontrol">Splunk Event QueryActivity</span> activity can be used with any workflow to search the Splunk event logs.</p> </div> <div class="section"><h2 class="title sectiontitle">Results</h2> <p class="p">Possible results for this activity are:</p> <div class="tablenoborder"><table cellpadding="4" cellspacing="0" summary="" id="event-query-splunk-activity__table_lg3_dm5_vy" class="table" frame="border" border="1" rules="all"><caption><span class="tablecap"><span class="table--title-label">Table 1. </span>Results</span></caption><colgroup><col /><col /></colgroup><thead class="thead" style="text-align:left;"><tr class="row"><th class="entry cellrowborder" style="vertical-align:top;" id="d70235e84">Result</th><th class="entry cellrowborder" style="vertical-align:top;" id="d70235e87">Description</th></tr></thead><tbody class="tbody"><tr class="row"><td class="entry cellrowborder" style="vertical-align:top;" headers="d70235e84 ">Success</td><td class="entry cellrowborder" style="vertical-align:top;" headers="d70235e87 ">Splunk</td></tr><tr class="row"><td class="entry cellrowborder" style="vertical-align:top;" headers="d70235e84 ">Failure</td><td class="entry cellrowborder" style="vertical-align:top;" headers="d70235e87 ">An error occurred while attempting to verify Splunk query. More error information is available in the activity output error.</td></tr></tbody></table> </div> </div> <div class="section" id="event-query-splunk-activity__section_tgt_ffm_3z"><h2 class="title sectiontitle">Input variables</h2> <p class="p">Input variables determine the initial behavior of the activity.</p> <div class="tablenoborder"><table cellpadding="4" cellspacing="0" summary="" id="event-query-splunk-activity__table_pgm_tfy_jr" class="table" frame="border" border="1" rules="all"><colgroup><col /><col /></colgroup><thead class="thead" style="text-align:left;"><tr class="row"><th class="entry cellrowborder" style="vertical-align:top;" id="d70235e136">Variable</th><th class="entry cellrowborder" style="vertical-align:top;" id="d70235e139">Description</th></tr></thead><tbody class="tbody"><tr class="row"><td class="entry cellrowborder" style="vertical-align:top;" headers="d70235e136 ">user</td><td class="entry cellrowborder" style="vertical-align:top;" headers="d70235e139 ">User name for the Splunk system.</td></tr><tr class="row"><td class="entry cellrowborder" style="vertical-align:top;" headers="d70235e136 ">password</td><td class="entry cellrowborder" style="vertical-align:top;" headers="d70235e139 ">Password for the Splunk system.</td></tr><tr class="row"><td class="entry cellrowborder" style="vertical-align:top;" headers="d70235e136 ">observables</td><td class="entry cellrowborder" style="vertical-align:top;" headers="d70235e139 ">The list of observables from <span class="ph">Trusted Security Circle</span> or the security incident task to search for. Returned in JSON format.</td></tr><tr class="row"><td class="entry cellrowborder" style="vertical-align:top;" headers="d70235e136 ">base_url</td><td class="entry cellrowborder" style="vertical-align:top;" headers="d70235e139 ">URL of the Splunk integration endpoint.</td></tr><tr class="row"><td class="entry cellrowborder" style="vertical-align:top;" headers="d70235e136 ">link_base_url</td><td class="entry cellrowborder" style="vertical-align:top;" headers="d70235e139 ">Link to the <span class="ph">Splunk</span> web interface, when available.</td></tr><tr class="row"><td class="entry cellrowborder" style="vertical-align:top;" headers="d70235e136 ">source</td><td class="entry cellrowborder" style="vertical-align:top;" headers="d70235e139 "><span class="ph">Source of the request to run the workflow. Supported inputs are: <span class="ph">Trusted Security Circles</span> or security incident task.</span></td></tr><tr class="row"><td class="entry cellrowborder" style="vertical-align:top;" headers="d70235e136 ">max_rows</td><td class="entry cellrowborder" style="vertical-align:top;" headers="d70235e139 "><span class="ph">Maximum rows to return from the query. The limit depends on the third-party integration. </span></td></tr><tr class="row"><td class="entry cellrowborder" style="vertical-align:top;" headers="d70235e136 ">days_to_search</td><td class="entry cellrowborder" style="vertical-align:top;" headers="d70235e139 "><span class="ph">Days to search from the current day backwards. Default is 7.</span></td></tr><tr class="row"><td class="entry cellrowborder" style="vertical-align:top;" headers="d70235e136 ">query</td><td class="entry cellrowborder" style="vertical-align:top;" headers="d70235e139 "><span class="ph">Search syntax. <code class="ph codeph">$(observable)</code> is the default. </span></td></tr></tbody></table> </div> </div> <div class="section"><h2 class="title sectiontitle">Output variables</h2> <p class="p">The output variables contain data that can be used in subsequent activities.</p> <div class="tablenoborder"><table cellpadding="4" cellspacing="0" summary="" id="event-query-splunk-activity__table_bnj_jfy_jr" class="table" frame="border" border="1" rules="all"><caption><span class="tablecap"><span class="table--title-label">Table 2. </span>Output variables</span></caption><colgroup><col /><col /></colgroup><thead class="thead" style="text-align:left;"><tr class="row"><th class="entry cellrowborder" style="vertical-align:top;" id="d70235e271">Variable</th><th class="entry cellrowborder" style="vertical-align:top;" id="d70235e274">Description</th></tr></thead><tbody class="tbody"><tr class="row"><td class="entry cellrowborder" style="vertical-align:top;" headers="d70235e271 ">output</td><td class="entry cellrowborder" style="vertical-align:top;" headers="d70235e274 "><span class="ph">Output of the query in JSON format.</span></td></tr></tbody></table> </div> </div> </div> <div class="related-links"> <div class="familylinks"> <div class="parentlink"><strong>Parent Topic:</strong> <a class="link" href="../../../product/security-operations-integrations/task/secops-integration-sightings-search-splunk-workflow.html" title="Security Operations - Splunk Sightings Search workflow is the implementation for the Splunk integration launched by the Security Operations Integration - Sightings Search workflow.">Security Operations Integration - Splunk Sightings Search workflow</a></div> </div> </div></body></html></div>