# # Splunk python script for double-urldecoding endpoint logs. # # This script should be defined in commands.conf as: # # [decode] # filename = decode.py # streaming = true # enableheader = false # # Usage: | decode # -- or maybe more efficient -- # | fields - _cd,_meta,_serial,_si,_sourcetype,_time | fields + _raw,host,source | decode # # # index=[indexname] - which index to target for results, if empty defaults to the main index # testmode=[true|false] - when true, writes file to var/run/splunk instead of var/spool/splunk # pathappend=[name] - name to append to output file, format is