<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: write script to deploy diag file in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/write-script-to-deploy-diag-file/m-p/746624#M22302</link>
    <description>&lt;P&gt;thank you, can you please let me know the python script to upload the diag file to splunk support&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 20 May 2025 20:43:10 GMT</pubDate>
    <dc:creator>harishsplunk7</dc:creator>
    <dc:date>2025-05-20T20:43:10Z</dc:date>
    <item>
      <title>write script to deploy diag file</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/write-script-to-deploy-diag-file/m-p/746609#M22297</link>
      <description>&lt;P&gt;Can anyone give me idea or script python to generate a diag file in splunk using python script&lt;BR /&gt;login to splunk support portal and enter the case number&amp;nbsp;Upload the file automatically&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 May 2025 19:18:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/write-script-to-deploy-diag-file/m-p/746609#M22297</guid>
      <dc:creator>harishsplunk7</dc:creator>
      <dc:date>2025-05-20T19:18:50Z</dc:date>
    </item>
    <item>
      <title>Re: write script to deploy diag file</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/write-script-to-deploy-diag-file/m-p/746619#M22298</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/259591"&gt;@harishsplunk7&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I wanted to check, are you using Windows or Linux UFs? UFs do not have Python installed as part of the Splunk deployment, therefore Python might not be best approach for this?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Tue, 20 May 2025 20:06:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/write-script-to-deploy-diag-file/m-p/746619#M22298</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-05-20T20:06:16Z</dc:date>
    </item>
    <item>
      <title>Re: write script to deploy diag file</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/write-script-to-deploy-diag-file/m-p/746621#M22300</link>
      <description>&lt;P&gt;we are have multiple splunk cluster and will need to generate a diag file everytime for search head or indexer..&amp;nbsp;&lt;/P&gt;&lt;P&gt;so need to automat the process of generating the diage and upload in splunk support case automatically.&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have script to generate a file and enter the case but spplunk support is will need api or some connection to login and search the case and upload the diag.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 May 2025 20:22:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/write-script-to-deploy-diag-file/m-p/746621#M22300</guid>
      <dc:creator>harishsplunk7</dc:creator>
      <dc:date>2025-05-20T20:22:55Z</dc:date>
    </item>
    <item>
      <title>Re: write script to deploy diag file</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/write-script-to-deploy-diag-file/m-p/746622#M22301</link>
      <description>&lt;P&gt;I think that just couple of lines sh script is enough as diag already have option to send and attach it to your case in splunk. You found more from&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.4.2/Troubleshooting/Generateadiag" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.4.2/Troubleshooting/Generateadiag&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 20 May 2025 20:34:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/write-script-to-deploy-diag-file/m-p/746622#M22301</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-05-20T20:34:47Z</dc:date>
    </item>
    <item>
      <title>Re: write script to deploy diag file</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/write-script-to-deploy-diag-file/m-p/746624#M22302</link>
      <description>&lt;P&gt;thank you, can you please let me know the python script to upload the diag file to splunk support&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 May 2025 20:43:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/write-script-to-deploy-diag-file/m-p/746624#M22302</guid>
      <dc:creator>harishsplunk7</dc:creator>
      <dc:date>2025-05-20T20:43:10Z</dc:date>
    </item>
    <item>
      <title>Re: write script to deploy diag file</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/write-script-to-deploy-diag-file/m-p/746627#M22303</link>
      <description>&lt;P&gt;Edit: deleted previous reply.&lt;/P&gt;&lt;P&gt;Nevermind, Im sure it originally said UF &lt;span class="lia-unicode-emoji" title=":face_with_rolling_eyes:"&gt;🙄&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 May 2025 20:50:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/write-script-to-deploy-diag-file/m-p/746627#M22303</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-05-20T20:50:01Z</dc:date>
    </item>
    <item>
      <title>Re: write script to deploy diag file</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/write-script-to-deploy-diag-file/m-p/746628#M22304</link>
      <description>That’s true, but at least for me it’s really rare to create diag on UF and then send it splunk. But if you need to do it regularly then it’s different story. But in those case I probably do e.g. with ansible play where I login into UF generate diag then copy that into full splunk instance and in last task I will send it to splunk with diag.&lt;BR /&gt;Those was steps what I manually did on last time I need to send diag from UF to splunk.</description>
      <pubDate>Tue, 20 May 2025 20:53:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/write-script-to-deploy-diag-file/m-p/746628#M22304</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-05-20T20:53:44Z</dc:date>
    </item>
    <item>
      <title>Re: write script to deploy diag file</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/write-script-to-deploy-diag-file/m-p/746629#M22305</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/259591"&gt;@harishsplunk7&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is your existing script doing? Perhaps we can help enhance this. Is there a specific reason you need it to be Python?&lt;/P&gt;&lt;P&gt;Does your existing script get around the problem that the diag command with --upload flag requires you to interactively enter your password? Im not sure how we can get around this issue?&lt;/P&gt;&lt;P&gt;Ultimately this activity could probably be repeated directly using the API that the diag upload CLI uses, however I am not sure if this information is publicly available.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Tue, 20 May 2025 20:59:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/write-script-to-deploy-diag-file/m-p/746629#M22305</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-05-20T20:59:57Z</dc:date>
    </item>
    <item>
      <title>Re: write script to deploy diag file</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/write-script-to-deploy-diag-file/m-p/746630#M22306</link>
      <description>&lt;P&gt;Just command&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;splunk diag --upload...&lt;/LI-CODE&gt;&lt;P&gt;and some needed parameters&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;Upload:
    Flags to control uploading files  Ex: splunk diag --upload
[...]
    --case-number=case-number
                        Case number to attach to, e.g. 200500
    --upload-user=UPLOAD_USER
                        splunk.com username to use for uploading
    --upload-description=UPLOAD_DESCRIPTION
                        description of file upload for Splunk support
    --firstchunk=chunk-number
                        For resuming upload of a multi-part upload; select the
                        first chunk to send
    --chunksize=chunk-size
                        Optional set the chunksize in bytes to be uploaded&lt;/PRE&gt;&lt;P&gt;These are described on above link.&lt;/P&gt;&lt;P&gt;When you are doing upload it’s not needed to do on node where you have created that diag file. Just move it into any splunk enterprise node which have https access to splunk support over internet.&lt;/P&gt;&lt;P&gt;If needed you can create script with any language you want to use, but as I already said, I probably use ansible for scripting. But it’s your decision based on your environment, needs and tools which you have.&lt;/P&gt;</description>
      <pubDate>Tue, 20 May 2025 21:17:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/write-script-to-deploy-diag-file/m-p/746630#M22306</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-05-20T21:17:34Z</dc:date>
    </item>
    <item>
      <title>Re: write script to deploy diag file</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/write-script-to-deploy-diag-file/m-p/746631#M22307</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/259591"&gt;@harishsplunk7&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just for anyone catching up, to confirm you specifically want to script the diag pushing, whilst this is available with --upload on the diag command it isnt possible to do this non-interactively because of the password request.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ive been doing some more digging on this on my local instance, the CLI uses python's getpass to request your password for the support portal/splunk.com interactively and to my knowledge its not possible to pipe/inject into this using anything like stdin, however I did find the python calls which actually do the upload.&lt;/P&gt;&lt;P&gt;Here is an example Python script which I believe may work for you, Ive not had chance to test it entirely yet, only in sections:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;import sys, os, glob
sys.path.append("/opt/splunk/lib/python3.9/site-packages")
from splunk.clilib import info_gather

# Locate latest diag file in SPLUNK_HOME
SPLUNK_HOME = os.environ.get("SPLUNK_HOME", "/opt/splunk")
diag_files = sorted(glob.glob(os.path.join(SPLUNK_HOME, "diag-*.tar.gz")))
if not diag_files:
    raise FileNotFoundError("No diag file found")
diag_file = diag_files[-1]

class CustomOptions:
    def __init__(self, upload_user, upload_password, case_number, upload_description):
        self.upload_user = upload_user
        self.upload_password = upload_password
        self.case_id = case_number
        self.upload_description = upload_description
        self.upload_uri="https://api.splunk.com"


options = CustomOptions(
    upload_user="your_username",
    upload_password="your_password",
    case_number="1234567",
    upload_description="Automated diag upload",
)

result = info_gather.upload_to_splunkcom(diag_file, options)
print("Upload result:", result)&lt;/LI-CODE&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Tue, 20 May 2025 21:36:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/write-script-to-deploy-diag-file/m-p/746631#M22307</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-05-20T21:36:29Z</dc:date>
    </item>
  </channel>
</rss>

