<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Getting error when trying to set up an alert for starting a Python script. in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Getting-error-when-trying-to-set-up-an-alert-for-starting-a/m-p/469758#M8342</link>
    <description>&lt;P&gt;Thank you, Rich, that definitely got it to run.  The python script checks for the --execute flag and shuts down if it doesn't see it.  We modeled it after a Splunk example python script.  Any idea how we should be passing the different arguments to the script?  I just want to alert on a certain event and pass along a value from one of fields in that event.  Let me know if I need to start a new Splunk Answer.  Thanks again.&lt;/P&gt;</description>
    <pubDate>Mon, 01 Jun 2020 21:36:45 GMT</pubDate>
    <dc:creator>msevcik</dc:creator>
    <dc:date>2020-06-01T21:36:45Z</dc:date>
    <item>
      <title>Getting error when trying to set up an alert for starting a Python script.</title>
      <link>https://community.splunk.com/t5/Alerting/Getting-error-when-trying-to-set-up-an-alert-for-starting-a/m-p/469756#M8340</link>
      <description>&lt;P&gt;I am trying to set up an alert that runs a script after finding a result. For some reason, we see this error each time we try to run the script:&lt;/P&gt;
&lt;PRE&gt;&lt;CODE&gt;06-01-2020 13:20:09.091 -0500 ERROR ModularUtility - Specified filename "/opt/splunk/etc/apps/TA-S3Deleter/bin/s3_file_deleter.py" not found in search path.

06-01-2020 13:20:09.091 -0500 ERROR sendmodalert - action=s3_file_deleter - Failed to find alert.execute.cmd "/opt/splunk/etc/apps/TA-S3Deleter/bin/s3_file_deleter.py".
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;Here is how the alert_actions.conf is set up:&lt;/P&gt;
&lt;PRE&gt;&lt;CODE&gt;[s3_file_deleter]
is_custom = 1
label = S3 File Deleter
description = This action passes along a value in filePath to a python script that will delete a file in an S3 bucket.
payload_format = json
alert.execute.cmd = /opt/splunk/etc/apps/TA-S3Deleter/bin/s3_file_deleter.py
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;The script definitely exists in that directory. I've reviewed a lot of the documentation on this, and there is no good example for simply running a python script. Any insight would be greatly appreciated. Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jun 2020 00:46:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Getting-error-when-trying-to-set-up-an-alert-for-starting-a/m-p/469756#M8340</guid>
      <dc:creator>msevcik</dc:creator>
      <dc:date>2020-06-09T00:46:07Z</dc:date>
    </item>
    <item>
      <title>Re: Getting error when trying to set up an alert for starting a Python script.</title>
      <link>https://community.splunk.com/t5/Alerting/Getting-error-when-trying-to-set-up-an-alert-for-starting-a/m-p/469757#M8341</link>
      <description>&lt;P&gt;Splunk does not allow random file paths in script commands.  Just specify the name of the .py file in &lt;CODE&gt;alert.execute.cmd&lt;/CODE&gt; and Splunk will fill in the rest.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jun 2020 21:12:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Getting-error-when-trying-to-set-up-an-alert-for-starting-a/m-p/469757#M8341</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-06-01T21:12:36Z</dc:date>
    </item>
    <item>
      <title>Re: Getting error when trying to set up an alert for starting a Python script.</title>
      <link>https://community.splunk.com/t5/Alerting/Getting-error-when-trying-to-set-up-an-alert-for-starting-a/m-p/469758#M8342</link>
      <description>&lt;P&gt;Thank you, Rich, that definitely got it to run.  The python script checks for the --execute flag and shuts down if it doesn't see it.  We modeled it after a Splunk example python script.  Any idea how we should be passing the different arguments to the script?  I just want to alert on a certain event and pass along a value from one of fields in that event.  Let me know if I need to start a new Splunk Answer.  Thanks again.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jun 2020 21:36:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Getting-error-when-trying-to-set-up-an-alert-for-starting-a/m-p/469758#M8342</guid>
      <dc:creator>msevcik</dc:creator>
      <dc:date>2020-06-01T21:36:45Z</dc:date>
    </item>
    <item>
      <title>Re: Getting error when trying to set up an alert for starting a Python script.</title>
      <link>https://community.splunk.com/t5/Alerting/Getting-error-when-trying-to-set-up-an-alert-for-starting-a/m-p/469759#M8343</link>
      <description>&lt;P&gt;Nevermind, I think I found where you can define the arguments sent to the script here: &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.3/AdvancedDev/CustomAlertScript"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.3/AdvancedDev/CustomAlertScript&lt;/A&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[myjavaaction]
. . .
alert.execute.cmd = java.path
alert.execute.cmd.arg.0 =  -jar
alert.execute.cmd.arg.1 = $SPLUNK_HOME/etc/apps/myapp/bin/my.jar
alert.execute.cmd.arg.2 = --execute
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 01 Jun 2020 21:46:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Getting-error-when-trying-to-set-up-an-alert-for-starting-a/m-p/469759#M8343</guid>
      <dc:creator>msevcik</dc:creator>
      <dc:date>2020-06-01T21:46:55Z</dc:date>
    </item>
  </channel>
</rss>

