<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Compare Output Values Between Splunk and Dynatrace Using DQL in DQL</title>
    <link>https://community.dynatrace.com/t5/DQL/Compare-Output-Values-Between-Splunk-and-Dynatrace-Using-DQL/m-p/278528#M2156</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;"I have the following Splunk query, and I'm trying to generate the corresponding output in Dynatrace."&lt;/P&gt;
&lt;P&gt;splunk query :-&lt;/P&gt;
&lt;P&gt;index=ngss*_sourcefire_secevents | rex field=index "(?&amp;lt;Local_Market&amp;gt;\w.*?)_"&lt;BR /&gt;| eval BlockedStatus =&lt;BR /&gt;case(Like(src_ip,"64.39.106.%") AND InlineResultID=4 ," Qualys Blocked",&lt;BR /&gt;Like(src_ip,"154.59.121.%") AND InlineResultID=4," Qualys Blocked",&lt;BR /&gt;Like(src_ip,"64.39.106.%") AND InlineResultID=0," Qualys Not Blocked",&lt;BR /&gt;Like(src_ip,"154.59.121.%") AND InlineResultID=0," Qualys Not Blocked",&lt;BR /&gt;NOT Like(src_ip,"64.39.106.%") AND InlineResultID=4,"Non Qualys Blocked",&lt;BR /&gt;NOT Like(src_ip,"154.59.121.%") AND InlineResultID=4,"Non Qualys Blocked",&lt;BR /&gt;NOT Like(src_ip,"64.39.106.%") AND InlineResultID=0,"Non Qualys Not Blocked",&lt;BR /&gt;NOT Like(src_ip,"154.59.121.%") AND InlineResultID=0,"Non Qualys Not Blocked")&lt;BR /&gt;| stats count by Local_Market BlockedStatus | rename eventtype as "Local Market",count as "Total Critical Events"&lt;/P&gt;
&lt;P&gt;corresponding DQL is as below , where i am getting Null value ..&lt;BR /&gt;Please not that in DQL Src_ip is consider as "InitiatorIP".&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&amp;nbsp;DQL query is as below :-&lt;/P&gt;
&lt;P&gt;fetch logs // scanLimitGBytes: , samplingRatio: 1000&lt;/P&gt;
&lt;P&gt;| filter contains(dt.security_context,"ngss")&lt;BR /&gt;| parse content,"""LD 'InlineResultID":' string:InlineResultID "," """&lt;BR /&gt;//| parse content, """LD 'InitiatorIP'[^,]{1,100}?:"InitiatorIP','""""&lt;BR /&gt;| fieldsAdd market = substring(dt.security_context, to: indexOf(dt.security_context, "_"))&lt;BR /&gt;| parse content, """ LD 'InitiatorIP\":\"' IPADDR:InitiatorIP """&lt;BR /&gt;| parse content, """ LD 'InitiatorIP=' IPADDR:InitiatorIP """&lt;BR /&gt;| fieldsadd QualysBlocked=if((like(SrcIP"154.59.121%") or like(SrcIP"64.39.106.%") AND contains(InlineResultID,"0") or contains(InlineResultID,"4")),QualysBlocked)&lt;BR /&gt;| fieldsadd QualysNotBlocked=if((like(SrcIP"64.39.106%") OR like(SrcIP"154.59.121.%") AND contains(InlineResultID,"0") or contains(InlineResultID,"4")),QualysNotBlocked)&lt;BR /&gt;| fieldsadd NonQualysBlocked=if((like(SrcIP"64.39.106%") or like(SrcIP"154.59.121%") AND contains(InlineResultID,"0") or contains(InlineResultID,"4")),NonQualysBlocked)&lt;BR /&gt;| fieldsadd NonQualysNotBlocked=if((like(SrcIP"64.39.106%") or like(SrcIP"154.59.121.%") AND contains(InlineResultID,"0") or contains(InlineResultID,"4")),NonQualysNotBlocked)&lt;BR /&gt;| fieldsADD BlockedStatus = coalesce(QualysBlocked,QualysnotBlocked,NonQualysBlocked,NonQualysNotBlocked)&lt;BR /&gt;//| fieldsADD Blockedstatus = coalesce(QualysBlocked,QualysnonBlocked)&lt;BR /&gt;| summarize count() ,by:{market,BlockedStatus}&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 17 Dec 2025 12:02:03 GMT</pubDate>
    <dc:creator>sharmas2</dc:creator>
    <dc:date>2025-12-17T12:02:03Z</dc:date>
    <item>
      <title>Compare Output Values Between Splunk and Dynatrace Using DQL</title>
      <link>https://community.dynatrace.com/t5/DQL/Compare-Output-Values-Between-Splunk-and-Dynatrace-Using-DQL/m-p/278528#M2156</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;"I have the following Splunk query, and I'm trying to generate the corresponding output in Dynatrace."&lt;/P&gt;
&lt;P&gt;splunk query :-&lt;/P&gt;
&lt;P&gt;index=ngss*_sourcefire_secevents | rex field=index "(?&amp;lt;Local_Market&amp;gt;\w.*?)_"&lt;BR /&gt;| eval BlockedStatus =&lt;BR /&gt;case(Like(src_ip,"64.39.106.%") AND InlineResultID=4 ," Qualys Blocked",&lt;BR /&gt;Like(src_ip,"154.59.121.%") AND InlineResultID=4," Qualys Blocked",&lt;BR /&gt;Like(src_ip,"64.39.106.%") AND InlineResultID=0," Qualys Not Blocked",&lt;BR /&gt;Like(src_ip,"154.59.121.%") AND InlineResultID=0," Qualys Not Blocked",&lt;BR /&gt;NOT Like(src_ip,"64.39.106.%") AND InlineResultID=4,"Non Qualys Blocked",&lt;BR /&gt;NOT Like(src_ip,"154.59.121.%") AND InlineResultID=4,"Non Qualys Blocked",&lt;BR /&gt;NOT Like(src_ip,"64.39.106.%") AND InlineResultID=0,"Non Qualys Not Blocked",&lt;BR /&gt;NOT Like(src_ip,"154.59.121.%") AND InlineResultID=0,"Non Qualys Not Blocked")&lt;BR /&gt;| stats count by Local_Market BlockedStatus | rename eventtype as "Local Market",count as "Total Critical Events"&lt;/P&gt;
&lt;P&gt;corresponding DQL is as below , where i am getting Null value ..&lt;BR /&gt;Please not that in DQL Src_ip is consider as "InitiatorIP".&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&amp;nbsp;DQL query is as below :-&lt;/P&gt;
&lt;P&gt;fetch logs // scanLimitGBytes: , samplingRatio: 1000&lt;/P&gt;
&lt;P&gt;| filter contains(dt.security_context,"ngss")&lt;BR /&gt;| parse content,"""LD 'InlineResultID":' string:InlineResultID "," """&lt;BR /&gt;//| parse content, """LD 'InitiatorIP'[^,]{1,100}?:"InitiatorIP','""""&lt;BR /&gt;| fieldsAdd market = substring(dt.security_context, to: indexOf(dt.security_context, "_"))&lt;BR /&gt;| parse content, """ LD 'InitiatorIP\":\"' IPADDR:InitiatorIP """&lt;BR /&gt;| parse content, """ LD 'InitiatorIP=' IPADDR:InitiatorIP """&lt;BR /&gt;| fieldsadd QualysBlocked=if((like(SrcIP"154.59.121%") or like(SrcIP"64.39.106.%") AND contains(InlineResultID,"0") or contains(InlineResultID,"4")),QualysBlocked)&lt;BR /&gt;| fieldsadd QualysNotBlocked=if((like(SrcIP"64.39.106%") OR like(SrcIP"154.59.121.%") AND contains(InlineResultID,"0") or contains(InlineResultID,"4")),QualysNotBlocked)&lt;BR /&gt;| fieldsadd NonQualysBlocked=if((like(SrcIP"64.39.106%") or like(SrcIP"154.59.121%") AND contains(InlineResultID,"0") or contains(InlineResultID,"4")),NonQualysBlocked)&lt;BR /&gt;| fieldsadd NonQualysNotBlocked=if((like(SrcIP"64.39.106%") or like(SrcIP"154.59.121.%") AND contains(InlineResultID,"0") or contains(InlineResultID,"4")),NonQualysNotBlocked)&lt;BR /&gt;| fieldsADD BlockedStatus = coalesce(QualysBlocked,QualysnotBlocked,NonQualysBlocked,NonQualysNotBlocked)&lt;BR /&gt;//| fieldsADD Blockedstatus = coalesce(QualysBlocked,QualysnonBlocked)&lt;BR /&gt;| summarize count() ,by:{market,BlockedStatus}&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Dec 2025 12:02:03 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/DQL/Compare-Output-Values-Between-Splunk-and-Dynatrace-Using-DQL/m-p/278528#M2156</guid>
      <dc:creator>sharmas2</dc:creator>
      <dc:date>2025-12-17T12:02:03Z</dc:date>
    </item>
    <item>
      <title>Re: Unexpected value in output - Splunk vs Dynatrace</title>
      <link>https://community.dynatrace.com/t5/DQL/Compare-Output-Values-Between-Splunk-and-Dynatrace-Using-DQL/m-p/291684#M2899</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/88797"&gt;@sharmas2&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;&lt;SPAN&gt;I just wanted to check in and see if you still need help with this. If so, I’d be happy to look into it for you!&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;&lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Please let me know what works best for you.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Dec 2025 12:01:32 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/DQL/Compare-Output-Values-Between-Splunk-and-Dynatrace-Using-DQL/m-p/291684#M2899</guid>
      <dc:creator>IzabelaRokita</dc:creator>
      <dc:date>2025-12-17T12:01:32Z</dc:date>
    </item>
  </channel>
</rss>

