<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic coldToFrozen script ERROR import command not found in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/coldToFrozen-script-ERROR-import-command-not-found/m-p/482156#M9431</link>
    <description>&lt;P&gt;I added socket to the import string so I can get the server hostname to append to the ARCHIVE_DIR path. Getting 2 BucketMover errors.&lt;/P&gt;

&lt;P&gt;import sys, os, gzip, shutil, subprocess, random, socket&lt;/P&gt;

&lt;P&gt;ARCHIVE_DIR = os.path.join('/path/to/nfsmnt', socket.gethostname())&lt;/P&gt;

&lt;P&gt;Error 1.   import: command not found&lt;BR /&gt;
Error 2.   syntax error near unexpected token '('    ARCHIVE_DIR = os.path.join('/path/to/nfsmnt', socket.gethostname())&lt;/P&gt;

&lt;P&gt;Can I use import socket in this script?&lt;/P&gt;

&lt;P&gt;Splunk Enterprise v 7.3.3&lt;/P&gt;</description>
    <pubDate>Sat, 11 Jan 2020 00:58:16 GMT</pubDate>
    <dc:creator>mikefg</dc:creator>
    <dc:date>2020-01-11T00:58:16Z</dc:date>
    <item>
      <title>coldToFrozen script ERROR import command not found</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/coldToFrozen-script-ERROR-import-command-not-found/m-p/482156#M9431</link>
      <description>&lt;P&gt;I added socket to the import string so I can get the server hostname to append to the ARCHIVE_DIR path. Getting 2 BucketMover errors.&lt;/P&gt;

&lt;P&gt;import sys, os, gzip, shutil, subprocess, random, socket&lt;/P&gt;

&lt;P&gt;ARCHIVE_DIR = os.path.join('/path/to/nfsmnt', socket.gethostname())&lt;/P&gt;

&lt;P&gt;Error 1.   import: command not found&lt;BR /&gt;
Error 2.   syntax error near unexpected token '('    ARCHIVE_DIR = os.path.join('/path/to/nfsmnt', socket.gethostname())&lt;/P&gt;

&lt;P&gt;Can I use import socket in this script?&lt;/P&gt;

&lt;P&gt;Splunk Enterprise v 7.3.3&lt;/P&gt;</description>
      <pubDate>Sat, 11 Jan 2020 00:58:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/coldToFrozen-script-ERROR-import-command-not-found/m-p/482156#M9431</guid>
      <dc:creator>mikefg</dc:creator>
      <dc:date>2020-01-11T00:58:16Z</dc:date>
    </item>
    <item>
      <title>Re: coldToFrozen script ERROR import command not found</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/coldToFrozen-script-ERROR-import-command-not-found/m-p/482157#M9432</link>
      <description>&lt;P&gt;I've tested against bin/splunk cmd python and the import and ARCHIVE_DIR statements work fine.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jan 2020 23:00:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/coldToFrozen-script-ERROR-import-command-not-found/m-p/482157#M9432</guid>
      <dc:creator>mikefg</dc:creator>
      <dc:date>2020-01-13T23:00:23Z</dc:date>
    </item>
    <item>
      <title>Re: coldToFrozen script ERROR import command not found</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/coldToFrozen-script-ERROR-import-command-not-found/m-p/482158#M9433</link>
      <description>&lt;P&gt;Can you please post the script that you try to run and please format it as code by either selecting the code and click to &lt;CODE&gt;101010&lt;/CODE&gt; menu item or press &lt;CODE&gt;Ctrl-K&lt;/CODE&gt; - thanks&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2020 00:17:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/coldToFrozen-script-ERROR-import-command-not-found/m-p/482158#M9433</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2020-01-14T00:17:15Z</dc:date>
    </item>
    <item>
      <title>Re: coldToFrozen script ERROR import command not found</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/coldToFrozen-script-ERROR-import-command-not-found/m-p/482159#M9434</link>
      <description>&lt;PRE&gt;&lt;CODE&gt;# This is an example script for archiving cold buckets. It must be modified
# to suit your individual needs, and we highly recommend testing this on a
# non-production instance before deploying it.

#import sys, os, gzip, shutil, subprocess, random
# Mike - import socket so we can get hostname

import sys, os, gzip, shutil, subprocess, random, socket

### CHANGE THIS TO YOUR ACTUAL ARCHIVE DIRECTORY!!!
#ARCHIVE_DIR = os.path.join(os.getenv('SPLUNK_HOME'), 'frozenarchive')
# Mike - static path to nfs mount and combine with hostname for full path

ARCHIVE_DIR = os.path.join('/mnt/nfs/splfrozen', socket.gethostname())

# For new style buckets (v4.2+), we can remove all files except for the rawdata.
# We can later rebuild all metadata and tsidx files with "splunk rebuild"
def handleNewBucket(base, files):
    print('Archiving bucket: ' + base)
    for f in files:
        full = os.path.join(base, f)
        if os.path.isfile(full):
            os.remove(full)

# For buckets created before 4.2, simply gzip the tsidx files
# To thaw these buckets, be sure to first unzip the tsidx files
def handleOldBucket(base, files):
    print('Archiving old-style bucket: ' + base)
    for f in files:
        full = os.path.join(base, f)
        if os.path.isfile(full) and (f.endswith('.tsidx') or f.endswith('.data')):
            fin = open(full, 'rb')
            fout = gzip.open(full + '.gz', 'wb')
            fout.writelines(fin)
            fout.close()
            fin.close()
            os.remove(full)

# This function is not called, but serves as an example of how to do
# the previous "flatfile" style export. This method is still not
# recommended as it is resource intensive
def handleOldFlatfileExport(base, files):
    command = ['exporttool', base, os.path.join(base, 'index.export'), 'meta::all']
    retcode = subprocess.call(command)
    if retcode != 0:
        sys.exit('exporttool failed with return code: ' + str(retcode))

    for f in files:
        full = os.path.join(base, f)
        if os.path.isfile(full):
            os.remove(full)
        elif os.path.isdir(full):
            shutil.rmtree(full)
        else:
            print('Warning: found irregular bucket file: ' + full)

if __name__ == "__main__":
    if len(sys.argv) != 2:
        sys.exit('usage: python coldToFrozenExample.py &amp;lt;bucket_dir_to_archive&amp;gt;')

    if not os.path.isdir(ARCHIVE_DIR):
        try:
            os.mkdir(ARCHIVE_DIR)
        except OSError:
            # Ignore already exists errors, another concurrent invokation may have already created this dir
            sys.stderr.write("mkdir warning: Directory '" + ARCHIVE_DIR + "' already exists\n")

    bucket = sys.argv[1]
    if not os.path.isdir(bucket):
        sys.exit('Given bucket is not a valid directory: ' + bucket)

    rawdatadir = os.path.join(bucket, 'rawdata')
    if not os.path.isdir(rawdatadir):
        sys.exit('No rawdata directory, given bucket is likely invalid: ' + bucket)

    files = os.listdir(bucket)
    journal = os.path.join(rawdatadir, 'journal.gz')
    if os.path.isfile(journal):
        handleNewBucket(bucket, files)
    else:
        handleOldBucket(bucket, files)

    if bucket.endswith('/'):
        bucket = bucket[:-1]

    indexname = os.path.basename(os.path.dirname(os.path.dirname(bucket)))
    destdir = os.path.join(ARCHIVE_DIR, indexname, os.path.basename(bucket))

    while os.path.isdir(destdir):
        print('Warning: This bucket already exists in the archive directory')
        print('Adding a random extension to this directory...')
        destdir += '.' + str(random.randrange(10))

    shutil.copytree(bucket, destdir)
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 14 Jan 2020 05:35:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/coldToFrozen-script-ERROR-import-command-not-found/m-p/482159#M9434</guid>
      <dc:creator>mikefg</dc:creator>
      <dc:date>2020-01-14T05:35:54Z</dc:date>
    </item>
    <item>
      <title>Re: coldToFrozen script ERROR import command not found</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/coldToFrozen-script-ERROR-import-command-not-found/m-p/482160#M9435</link>
      <description>&lt;P&gt;Got it working. Combination of indent problems (python), windows to linux fixed by using dos2unix, missing ssl fixed by moving _hashlib.so, and removing unneeded parts of the script lines 25-55.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jan 2020 22:30:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/coldToFrozen-script-ERROR-import-command-not-found/m-p/482160#M9435</guid>
      <dc:creator>mikefg</dc:creator>
      <dc:date>2020-01-17T22:30:07Z</dc:date>
    </item>
  </channel>
</rss>

