<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: External lookup Python Script: How to send a custom error message to Splunk SH UI in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/External-lookup-Python-Script-How-to-send-a-custom-error-message/m-p/487322#M136192</link>
    <description>&lt;P&gt;@jkat54 Thank you so much for your response, much appreciated!&lt;/P&gt;

&lt;P&gt;I'm using Splunk 7+, Can you please bit elaborate how can i make use of the search commands doc. &lt;/P&gt;

&lt;P&gt;If possible any examples please!&lt;/P&gt;</description>
    <pubDate>Sun, 26 Apr 2020 12:31:46 GMT</pubDate>
    <dc:creator>prabhan</dc:creator>
    <dc:date>2020-04-26T12:31:46Z</dc:date>
    <item>
      <title>External lookup Python Script: How to send a custom error message to Splunk SH UI</title>
      <link>https://community.splunk.com/t5/Splunk-Search/External-lookup-Python-Script-How-to-send-a-custom-error-message/m-p/487320#M136190</link>
      <description>&lt;P&gt;Hi Splunkers,&lt;/P&gt;

&lt;P&gt;My external lookup working just fine and the results are proper. &lt;/P&gt;

&lt;P&gt;As mentioned in the below screenshot my_test_lookup.py is available in my /etc/apps/[my_app]/bin/my_test_lookup.py.&lt;/P&gt;

&lt;P&gt;I don't have any issue with the external lookup  with python script. &lt;/P&gt;

&lt;P&gt;&lt;IMG src="https://community.splunk.com/storage/temp/291583-capture.png" alt="alt text" /&gt; &lt;/P&gt;

&lt;P&gt;Is there any way to send a custom message from python script to splunk GUI whenever the search event matches the custom limit number(1000). &lt;/P&gt;

&lt;P&gt;This limit is not from the splunk configs. this limit has been provided in my external lookup python script. &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;r = csv.DictReader(infile)
header = r.fieldnames
w = csv.DictWriter(outfile, fieldnames=r.fieldnames)
w.writeheader()

event_count = 0
search_limit = 1000
for result in r:
    if result[group_field]:
        result[field1] = "test1"
        result[field2] = "testfiedl2"
        w.writerow(result)
        event_count += 1
        if event_count == search_limit:
            reach_limit_msg = "Reached Limit %d" % event_count
            send_message(reach_limit_msg)
            print("Reached Limit %d" % event_count)
            logger.warning("Reached Limit %d" % event_count)
            sys.exit(0)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;It may be a kind of popup saying your search limit &lt;CODE&gt;1000 exceeded&lt;/CODE&gt; or something like below mentioned screenshot.&lt;BR /&gt;
&lt;IMG src="https://community.splunk.com/storage/temp/291584-capture1.png" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;FYI: I have already tried bulletin message by referencing this &lt;A href="https://answers.splunk.com/answers/338137/how-to-create-a-bulletin-message-to-display-to-use.html" target="_blank"&gt;url&lt;/A&gt; . It worked like charm, but it sends a bulletin message to all the users who logged in, but i would like to send a message to only the person who fired the SPL query.&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;Please help, Thanks in advance _/_.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 05:13:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/External-lookup-Python-Script-How-to-send-a-custom-error-message/m-p/487320#M136190</guid>
      <dc:creator>prabhan</dc:creator>
      <dc:date>2020-09-30T05:13:37Z</dc:date>
    </item>
    <item>
      <title>Re: External lookup Python Script: How to send a custom error message to Splunk SH UI</title>
      <link>https://community.splunk.com/t5/Splunk-Search/External-lookup-Python-Script-How-to-send-a-custom-error-message/m-p/487321#M136191</link>
      <description>&lt;P&gt;If you switch to a newer version of the search commands it seems pretty easy.  See the "doc" sections of the commands here:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://github.com/splunk/splunk-sdk-python/tree/master/examples/searchcommands_app/package/bin/"&gt;https://github.com/splunk/splunk-sdk-python/tree/master/examples/searchcommands_app/package/bin/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 26 Apr 2020 10:41:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/External-lookup-Python-Script-How-to-send-a-custom-error-message/m-p/487321#M136191</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2020-04-26T10:41:22Z</dc:date>
    </item>
    <item>
      <title>Re: External lookup Python Script: How to send a custom error message to Splunk SH UI</title>
      <link>https://community.splunk.com/t5/Splunk-Search/External-lookup-Python-Script-How-to-send-a-custom-error-message/m-p/487322#M136192</link>
      <description>&lt;P&gt;@jkat54 Thank you so much for your response, much appreciated!&lt;/P&gt;

&lt;P&gt;I'm using Splunk 7+, Can you please bit elaborate how can i make use of the search commands doc. &lt;/P&gt;

&lt;P&gt;If possible any examples please!&lt;/P&gt;</description>
      <pubDate>Sun, 26 Apr 2020 12:31:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/External-lookup-Python-Script-How-to-send-a-custom-error-message/m-p/487322#M136192</guid>
      <dc:creator>prabhan</dc:creator>
      <dc:date>2020-04-26T12:31:46Z</dc:date>
    </item>
    <item>
      <title>Re: External lookup Python Script: How to send a custom error message to Splunk SH UI</title>
      <link>https://community.splunk.com/t5/Splunk-Search/External-lookup-Python-Script-How-to-send-a-custom-error-message/m-p/487323#M136193</link>
      <description>&lt;P&gt;Did you look at the link I provided?  There were plenty of examples.&lt;/P&gt;</description>
      <pubDate>Sun, 26 Apr 2020 13:21:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/External-lookup-Python-Script-How-to-send-a-custom-error-message/m-p/487323#M136193</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2020-04-26T13:21:31Z</dc:date>
    </item>
    <item>
      <title>Re: External lookup Python Script: How to send a custom error message to Splunk SH UI</title>
      <link>https://community.splunk.com/t5/Splunk-Search/External-lookup-Python-Script-How-to-send-a-custom-error-message/m-p/487324#M136194</link>
      <description>&lt;P&gt;@jkat54  Yes, I have checked that. So as per my understanding we can create a custom search command for my use case. but i already started working with the External Lookup. Now there is no option to change it from external lookup to custom search command.&lt;/P&gt;</description>
      <pubDate>Sun, 26 Apr 2020 13:56:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/External-lookup-Python-Script-How-to-send-a-custom-error-message/m-p/487324#M136194</guid>
      <dc:creator>prabhan</dc:creator>
      <dc:date>2020-04-26T13:56:58Z</dc:date>
    </item>
    <item>
      <title>Re: External lookup Python Script: How to send a custom error message to Splunk SH UI</title>
      <link>https://community.splunk.com/t5/Splunk-Search/External-lookup-Python-Script-How-to-send-a-custom-error-message/m-p/487325#M136195</link>
      <description>&lt;P&gt;Oh right I missed that.  The SPL command might be easier but if you want to try the scripted lookup you should check out intersplunk.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://python.hotexamples.com/examples/splunk/Intersplunk/-/python-intersplunk-class-examples.html"&gt;https://python.hotexamples.com/examples/splunk/Intersplunk/-/python-intersplunk-class-examples.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 26 Apr 2020 22:20:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/External-lookup-Python-Script-How-to-send-a-custom-error-message/m-p/487325#M136195</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2020-04-26T22:20:47Z</dc:date>
    </item>
    <item>
      <title>Re: External lookup Python Script: How to send a custom error message to Splunk SH UI</title>
      <link>https://community.splunk.com/t5/Splunk-Search/External-lookup-Python-Script-How-to-send-a-custom-error-message/m-p/487326#M136196</link>
      <description>&lt;P&gt;@jkat54 Scripted lookup not rely on intersplunk, &lt;BR /&gt;
Here is my findings- &lt;EM&gt;Python search commands rely on Intersplunk.py to grab events from the search pipeline and pass the modified events back. The arguments passed to your script&lt;BR /&gt;
in sys.argv are the same arguments you use when searching with the command.&lt;/EM&gt;&lt;/P&gt;

&lt;P&gt;So we need to identify some other way to display a custom message to the Splunk SH.&lt;/P&gt;

&lt;P&gt;I just wanted to print the error in the Splunk search head. whenever it cross the limit.&lt;/P&gt;

&lt;P&gt;As per my research its not possible i guess. please let me know if you have any other idea?? pls..&lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2020 16:17:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/External-lookup-Python-Script-How-to-send-a-custom-error-message/m-p/487326#M136196</guid>
      <dc:creator>prabhan</dc:creator>
      <dc:date>2020-04-27T16:17:45Z</dc:date>
    </item>
    <item>
      <title>Re: External lookup Python Script: How to send a custom error message to Splunk SH UI</title>
      <link>https://community.splunk.com/t5/Splunk-Search/External-lookup-Python-Script-How-to-send-a-custom-error-message/m-p/487327#M136197</link>
      <description>&lt;P&gt;I mean it couldn't hurt to try...&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;except Exception, e:
    import traceback

    stack = traceback.format_exc()
    splunk.Intersplunk.generateErrorResults(str(e))
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 27 Apr 2020 23:28:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/External-lookup-Python-Script-How-to-send-a-custom-error-message/m-p/487327#M136197</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2020-04-27T23:28:11Z</dc:date>
    </item>
  </channel>
</rss>

