Skip to content

Releases: techservicesillinois/SecOps-Powershell-Splunk

v1.1.9

Choose a tag to compare

@baristaTam baristaTam released this 16 Jul 14:45
c8df522

[1.1.9] - 2026-07-16

Changed

  • Export-SplunkData
    • Fix file export issue that generates multiple files when paging instead of coalescing results
    • Conditionally add "search" to beginning of search to allow for searches that instead begin with pipes ie '| inputlookup lookup'
    • Update example to no longer include workaround for searches that begin with pipes

v1.1.8

Choose a tag to compare

@mabaumgartner mabaumgartner released this 24 Jun 21:10
15609a9

[1.1.8] - 2026-06-24

Changed

  • UofISplunkCloud.psm1
    • fixed path capitalization that was preventing the module from loading function in Linux
  • Update GitHub actions for checkout

v1.1.7

Choose a tag to compare

@baristaTam baristaTam released this 01 Jun 18:55
8da6d81

[1.1.7] - 2026-05-28

Changed

  • Export-SplunkData & Update-SplunkLookup:
    • Updated Splunk REST search job creation to use the shared app namespace (servicesNS/nobody/) instead of the authenticated user namespace. This avoids severe latency caused by user-specific namespace resolution while preserving app-context search behavior.

v1.1.6

Choose a tag to compare

@baristaTam baristaTam released this 04 Mar 19:20
069e133

[1.1.6] - 2026-03-04

Changed

  • Export-SplunkData: File generation in transient execution environments (e.g. Azure Automation runbooks) is susceptible to intermittent I/O failures. Added retry logic to handle cases where output files are not written due to short-lived environment instability.

v1.1.5

Choose a tag to compare

@mabaumgartner mabaumgartner released this 28 May 14:40
efdc84a

Changed

  • Removed a previous v1.1.1 fix in Send-SplunkHECEvent.ps1 to address a case where Splunk was treating unicode quotation characters as U+0022. PowerShell escapes U+0022 with ConvertTo-Json. This change removes the escapes of the unicode quote characters since this now causes an error. Splunk must have resolved this bug and therefore the pervious fix was preventing some events from being accepted by the HEC endpoint.
  • Update GitHub actions for checkout and pr-reviews-reminder-action workflows.
  • README.md - update the end of support to November 2026 to align with PowerShell 7.4

v1.1.4

Choose a tag to compare

@baristaTam baristaTam released this 06 Nov 23:32
d20497c

[1.1.4] - 2024-11-06

Changed

  • Export-SplunkData.ps1: Added new parameters "Offset" and "MaxResults" to add the functionality of offsetting results due to the 50000 event limit within the Splunk Cloud API.

v1.1.3

Choose a tag to compare

@mabaumgartner mabaumgartner released this 03 May 16:29
0e25d54

[1.1.3] - 2023-05-01

Changed

  • Send-SplunkHECEvent.ps1 now has a parameter SkipCertificateCheck to allow for connections to dev environments with self-signed certificates on the HEC endpoint.

v1.1.2

Choose a tag to compare

@baristaTam baristaTam released this 31 Mar 19:23
e95ed14

[1.1.2] - 2023-03-31

Changed

  • Added "count" parameter and set to 0 so results are no longer limited to 100.

v1.1.1

Choose a tag to compare

@mabaumgartner mabaumgartner released this 04 Oct 15:14
5ad8a21

[1.1.1] - 2022-09-06

Changed

  • Provided a fix in Send-SplunkHECEvent.ps1 to address a case where Splunk was treating unicode quotation characters as U+0022. PowerShell escapes U+0022 with ConvertTo-Json. This fix also escapes the other unicode quotation characters to prevent an error from Splunk HEC.
  • Added a parameter to the ConvertTo-Json command to allow processing of deeper JSON objects.

v1.1.0

Choose a tag to compare

@baristaTam baristaTam released this 26 Aug 17:41
a1db886

[1.1.0] - 2022-08-23

Added

  • Send-SplunkHECEvent which sends one or more PowerShell objects to a Splunk HTTP Event Collector (HEC) endpoint as a json object.