Default Version 1.0.13
August 6, 2025
August 6, 2025
Splunk Enterprise, Splunk Cloud
Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0
Log in to rate this app
This custom streaming search command was developed to handle JSON data sources that contain arrays of objects, which is a common problem with API data sources such as CrowdStrike and Google Workspace. The command adds additional fields using the value from the provided key, and either a specific child or all children other than the key.
Log in to report this app listing.