<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Python script to read Splunk data in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Python-script-to-read-Splunk-data/m-p/569150#M198368</link>
    <description>&lt;P&gt;Sorry for the confusion.&amp;nbsp; I am trying with 2 different approaches with the same login credentials.&amp;nbsp; The 1st one is regular Web access with failed 401 error and the 2nd one is connection via Splunk-SDK client which is successful.&amp;nbsp; It is confirmed with&amp;nbsp;&lt;SPAN&gt;&amp;lt;splunklib.client.Service&amp;nbsp;object&amp;nbsp;at&amp;nbsp;0x0000013682881790&amp;gt; for print(service) statement.&amp;nbsp; For my 1st Web access connection, my question is how to login Spunk website correctly.&amp;nbsp; For my 2nd Splunk client connection, my question is how to modify its "search" string to get correct results.&amp;nbsp; I am fine with either one.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 30 Sep 2021 13:25:39 GMT</pubDate>
    <dc:creator>bergen288</dc:creator>
    <dc:date>2021-09-30T13:25:39Z</dc:date>
    <item>
      <title>Python script to read Splunk data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Python-script-to-read-Splunk-data/m-p/568590#M198159</link>
      <description>&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;I&amp;nbsp;need&amp;nbsp;to&amp;nbsp;collect&amp;nbsp;Specific&amp;nbsp;Splunk&amp;nbsp;data&amp;nbsp;for&amp;nbsp;business&amp;nbsp;analysis.&amp;nbsp;&amp;nbsp;My&amp;nbsp;target&amp;nbsp;URL&amp;nbsp;is&amp;nbsp;&lt;A href="https://splunk.usce.l.az.fisv.cloud/en-US/app/epayments/postpayee_success_and_failure" target="_blank"&gt;https://splunk.usce.l.az.fisv.cloud/en-US/app/epayments/postpayee_success_and_failure&lt;/A&gt;?&lt;/SPAN&gt;&lt;SPAN&gt;form.SponsorId&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;*&amp;amp;&lt;/SPAN&gt;&lt;SPAN&gt;form.SubscriberId&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;*&amp;amp;&lt;/SPAN&gt;&lt;SPAN&gt;form.CorrelationId&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;*&amp;amp;&lt;/SPAN&gt;&lt;SPAN&gt;form.Status&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;*&amp;amp;&lt;/SPAN&gt;&lt;SPAN&gt;form.Exception&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;-&amp;amp;&lt;/SPAN&gt;&lt;SPAN&gt;form.timespan.earliest&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;-7d%40h&amp;amp;&lt;/SPAN&gt;&lt;SPAN&gt;form.timespan.latest&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;now.&amp;nbsp;&amp;nbsp;After&amp;nbsp;login&amp;nbsp;with&amp;nbsp;my&amp;nbsp;username/password,&amp;nbsp;it&amp;nbsp;will&amp;nbsp;show&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;"Post&amp;nbsp;Payee&amp;nbsp;Exception&amp;nbsp;List"&lt;/SPAN&gt;&lt;SPAN&gt;.&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;SPAN&gt;I&amp;nbsp;am&amp;nbsp;trying&amp;nbsp;to&amp;nbsp;write&amp;nbsp;a&amp;nbsp;Python&amp;nbsp;script&amp;nbsp;to&amp;nbsp;read&amp;nbsp;Splunk&amp;nbsp;data&amp;nbsp;in&amp;nbsp;last&amp;nbsp;7&amp;nbsp;days.&amp;nbsp;&amp;nbsp;Below&amp;nbsp;is&amp;nbsp;my&amp;nbsp;code:&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;SPAN&gt;session&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;requests.Session()&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;response&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;session.post(LOGIN_URL,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;auth&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;HTTPBasicAuth(user,&amp;nbsp;password),&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;verify&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;False)&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;print(response.status_code)&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;SPAN&gt;The&amp;nbsp;user/password&amp;nbsp;are&amp;nbsp;the&amp;nbsp;same&amp;nbsp;ones&amp;nbsp;for&amp;nbsp;Web&amp;nbsp;access&amp;nbsp;and&amp;nbsp;the&amp;nbsp;LOGIN_URL&amp;nbsp;is&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;A href="https://splunk.usce.l.az.fisv.cloud/en-US/account/login?return_to=%2Fen-US%2F" target="_blank"&gt;https://splunk.usce.l.az.fisv.cloud/en-US/account/login?return_to=%2Fen-US%2F&lt;/A&gt;'&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;However,&amp;nbsp;the&amp;nbsp;response&amp;nbsp;status&amp;nbsp;code&amp;nbsp;is&amp;nbsp;401&amp;nbsp;which&amp;nbsp;is&amp;nbsp;a&amp;nbsp;failure.&amp;nbsp;&amp;nbsp;What&lt;/SPAN&gt;&lt;SPAN&gt;'s&amp;nbsp;the&amp;nbsp;correct&amp;nbsp;Python&amp;nbsp;way&amp;nbsp;to&amp;nbsp;login&amp;nbsp;to&amp;nbsp;Splunk&amp;nbsp;website?&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;SPAN&gt;In&amp;nbsp;addition,&amp;nbsp;I&amp;nbsp;am&amp;nbsp;trying&amp;nbsp;to&amp;nbsp;connect&amp;nbsp;to&amp;nbsp;Splunk&amp;nbsp;server&amp;nbsp;with&amp;nbsp;Splunk-SDK&amp;nbsp;package&amp;nbsp;via&amp;nbsp;port&amp;nbsp;8089.&amp;nbsp;&amp;nbsp;Below&amp;nbsp;is&amp;nbsp;my&amp;nbsp;Python&amp;nbsp;code:&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;SPAN&gt;import&amp;nbsp;splunklib.client&amp;nbsp;as&amp;nbsp;client&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;import&amp;nbsp;splunklib.results&amp;nbsp;as&amp;nbsp;results&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;SPAN&gt;HOST&amp;nbsp;=&amp;nbsp;"splunk.usce.l.az.fisv.cloud"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;PORT&amp;nbsp;=&amp;nbsp;8089&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;credentials&amp;nbsp;=&amp;nbsp;get_splunk_pwd()&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;username&amp;nbsp;=&amp;nbsp;credentials['&lt;/SPAN&gt;&lt;SPAN&gt;username&lt;/SPAN&gt;&lt;SPAN&gt;']&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;password&amp;nbsp;=&amp;nbsp;credentials['&lt;/SPAN&gt;&lt;SPAN&gt;password&lt;/SPAN&gt;&lt;SPAN&gt;']&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;SPAN&gt;service&amp;nbsp;=&amp;nbsp;client.connect(&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;host=HOST,&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;port=PORT,&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;username=username,&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;password=password)&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;print(service)&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;rr&amp;nbsp;=&amp;nbsp;results.ResultsReader(service.jobs.export("search&amp;nbsp;index=_internal&amp;nbsp;earliest=-24h&amp;nbsp;|&amp;nbsp;head&amp;nbsp;5"))&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;for&amp;nbsp;result&amp;nbsp;in&amp;nbsp;rr:&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;if&amp;nbsp;isinstance(result,&amp;nbsp;results.Message):&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;#&amp;nbsp;Diagnostic&amp;nbsp;messages&amp;nbsp;might&amp;nbsp;be&amp;nbsp;returned&amp;nbsp;in&amp;nbsp;the&amp;nbsp;results&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;print('&lt;/SPAN&gt;&lt;SPAN&gt;%s:&amp;nbsp;%s&lt;/SPAN&gt;&lt;SPAN&gt;'&amp;nbsp;%&amp;nbsp;(result.type,&amp;nbsp;result.message)&amp;nbsp;)&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;elif&amp;nbsp;isinstance(result,&amp;nbsp;dict):&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;#&amp;nbsp;Normal&amp;nbsp;events&amp;nbsp;are&amp;nbsp;returned&amp;nbsp;as&amp;nbsp;dicts&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;print(result)&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Below&amp;nbsp;is&amp;nbsp;the&amp;nbsp;output.&amp;nbsp;&amp;nbsp;It&amp;nbsp;looks&amp;nbsp;like&amp;nbsp;the&amp;nbsp;Splunk&amp;nbsp;connection&amp;nbsp;is&amp;nbsp;established&amp;nbsp;successfully.&amp;nbsp;&amp;nbsp;But&amp;nbsp;the&amp;nbsp;serarch&amp;nbsp;is&amp;nbsp;invalid.&amp;nbsp;&amp;nbsp;What'&lt;/SPAN&gt;&lt;SPAN&gt;s&amp;nbsp;the&amp;nbsp;valid&amp;nbsp;search&amp;nbsp;string&amp;nbsp;based&amp;nbsp;on&amp;nbsp;my&amp;nbsp;target&amp;nbsp;URL&amp;nbsp;in&amp;nbsp;1st&amp;nbsp;line?&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;lt;splunklib.client.Service&amp;nbsp;object&amp;nbsp;at&amp;nbsp;0x0000029461421790&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;DEBUG:&amp;nbsp;Configuration&amp;nbsp;initialization&amp;nbsp;for&amp;nbsp;/opt/splunk/etc&amp;nbsp;took&amp;nbsp;91ms&amp;nbsp;when&amp;nbsp;dispatching&amp;nbsp;a&amp;nbsp;search&amp;nbsp;(search&amp;nbsp;ID:&amp;nbsp;1632765670.57370_31B6A7A0-BF6B-46EF-BD46-2CF0D6AB351A)&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;DEBUG:&amp;nbsp;Invalid&amp;nbsp;eval&amp;nbsp;expression&amp;nbsp;for&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;'EVAL-SessionDateTime'&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;in&amp;nbsp;stanza&amp;nbsp;[source::dbmon-tail://*/CCAuditLogSelect]:&amp;nbsp;The&amp;nbsp;expression&amp;nbsp;is&amp;nbsp;malformed.&amp;nbsp;An&amp;nbsp;unexpected&amp;nbsp;character&amp;nbsp;is&amp;nbsp;reached&amp;nbsp;at&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;'“%Y-%m-%d&amp;nbsp;%H:%M:%S.%3N”)'&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;DEBUG:&amp;nbsp;Invalid&amp;nbsp;eval&amp;nbsp;expression&amp;nbsp;for&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;'EVAL-TrxDateTime'&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;in&amp;nbsp;stanza&amp;nbsp;[source::dbmon-tail://*/CCAuditLogSelect]:&amp;nbsp;The&amp;nbsp;expression&amp;nbsp;is&amp;nbsp;malformed.&amp;nbsp;An&amp;nbsp;unexpected&amp;nbsp;character&amp;nbsp;is&amp;nbsp;reached&amp;nbsp;at&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;'“%Y-%m-%d&amp;nbsp;%H:%M:%S.%3N”)'&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;DEBUG:&amp;nbsp;base&amp;nbsp;lispy:&amp;nbsp;[&amp;nbsp;AND&amp;nbsp;index::_internal&amp;nbsp;]&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;DEBUG:&amp;nbsp;search&amp;nbsp;context:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;user&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;"xzhang"&lt;/SPAN&gt;&lt;SPAN&gt;,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;app&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;"search"&lt;/SPAN&gt;&lt;SPAN&gt;,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;bs-pathname&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;"/opt/splunk/etc"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 27 Sep 2021 18:08:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Python-script-to-read-Splunk-data/m-p/568590#M198159</guid>
      <dc:creator>bergen288</dc:creator>
      <dc:date>2021-09-27T18:08:31Z</dc:date>
    </item>
    <item>
      <title>Re: Python script to read Splunk data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Python-script-to-read-Splunk-data/m-p/568617#M198161</link>
      <description>&lt;P&gt;None of the DEBUG messages shown indicate a problem with the search query.&amp;nbsp; Two of them refer to errors in a props.conf file ("Invalid eval expression") and the others are just informational.&amp;nbsp; What leads you to believe there's something wrong with the query?&lt;/P&gt;&lt;P&gt;The error 401 indicates you're not passing your login credentials correctly.&amp;nbsp; &amp;nbsp;See&amp;nbsp;&lt;A href="https://dev.splunk.com/enterprise/docs/devtools/python/sdk-python/howtousesplunkpython/howtoconnectpython/" target="_blank"&gt;https://dev.splunk.com/enterprise/docs/devtools/python/sdk-python/howtousesplunkpython/howtoconnectpython/ &lt;/A&gt;for assistance.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Sep 2021 20:26:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Python-script-to-read-Splunk-data/m-p/568617#M198161</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-09-27T20:26:43Z</dc:date>
    </item>
    <item>
      <title>Re: Python script to read Splunk data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Python-script-to-read-Splunk-data/m-p/568740#M198206</link>
      <description>&lt;P&gt;First, I don't see any valid search result with print(result) statement.&amp;nbsp; My key question is how to define search string for&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;A href="https://splunk.usce.l.az.fisv.cloud/en-US/app/epayments/postpayee_success_and_failure" target="_blank" rel="nofollow noopener noreferrer"&gt;https://splunk.usce.l.az.fisv.cloud/en-US/app/epayments/postpayee_success_and_failure&lt;/A&gt;?&lt;/SPAN&gt;&lt;SPAN&gt;form.SponsorId&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;*&amp;amp;&lt;/SPAN&gt;&lt;SPAN&gt;form.SubscriberId&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;*&amp;amp;&lt;/SPAN&gt;&lt;SPAN&gt;form.CorrelationId&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;*&amp;amp;&lt;/SPAN&gt;&lt;SPAN&gt;form.Status&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;*&amp;amp;&lt;/SPAN&gt;&lt;SPAN&gt;form.Exception&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;-&amp;amp;&lt;/SPAN&gt;&lt;SPAN&gt;form.timespan.earliest&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;-7d%40h&amp;amp;&lt;/SPAN&gt;&lt;SPAN&gt;form.timespan.latest&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;now after Splunk client connection?&amp;nbsp; Second, I don't see Splunk website login example in your link?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Sep 2021 14:18:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Python-script-to-read-Splunk-data/m-p/568740#M198206</guid>
      <dc:creator>bergen288</dc:creator>
      <dc:date>2021-09-28T14:18:54Z</dc:date>
    </item>
    <item>
      <title>Re: Python script to read Splunk data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Python-script-to-read-Splunk-data/m-p/569140#M198361</link>
      <description>&lt;P&gt;You don't get any results back because of the error 401, which indicates an authentication failure.&amp;nbsp; Fixing the search query will not change that.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Authentication is done by the client.connect call.&amp;nbsp; Carefully compare your code to that in the examples at dev.splunk.com.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2021 13:08:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Python-script-to-read-Splunk-data/m-p/569140#M198361</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-09-30T13:08:35Z</dc:date>
    </item>
    <item>
      <title>Re: Python script to read Splunk data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Python-script-to-read-Splunk-data/m-p/569150#M198368</link>
      <description>&lt;P&gt;Sorry for the confusion.&amp;nbsp; I am trying with 2 different approaches with the same login credentials.&amp;nbsp; The 1st one is regular Web access with failed 401 error and the 2nd one is connection via Splunk-SDK client which is successful.&amp;nbsp; It is confirmed with&amp;nbsp;&lt;SPAN&gt;&amp;lt;splunklib.client.Service&amp;nbsp;object&amp;nbsp;at&amp;nbsp;0x0000013682881790&amp;gt; for print(service) statement.&amp;nbsp; For my 1st Web access connection, my question is how to login Spunk website correctly.&amp;nbsp; For my 2nd Splunk client connection, my question is how to modify its "search" string to get correct results.&amp;nbsp; I am fine with either one.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2021 13:25:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Python-script-to-read-Splunk-data/m-p/569150#M198368</guid>
      <dc:creator>bergen288</dc:creator>
      <dc:date>2021-09-30T13:25:39Z</dc:date>
    </item>
    <item>
      <title>Re: Python script to read Splunk data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Python-script-to-read-Splunk-data/m-p/569151#M198369</link>
      <description>&lt;P&gt;Sorry, I replied to your previous response.&amp;nbsp; Here you go again:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Sorry for the confusion.&amp;nbsp; I am trying with 2 different approaches with the same login credentials.&amp;nbsp; The 1st one is regular Web access with failed 401 error and the 2nd one is connection via Splunk-SDK client which is successful.&amp;nbsp; It is confirmed with&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;splunklib.client.Service&amp;nbsp;object&amp;nbsp;at&amp;nbsp;0x0000013682881790&amp;gt; for print(service) statement.&amp;nbsp; For my 1st Web access connection, my question is how to login Spunk website correctly.&amp;nbsp; For my 2nd Splunk client connection, my question is how to modify its "search" string to get correct results.&amp;nbsp; I am fine with either one.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2021 13:28:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Python-script-to-read-Splunk-data/m-p/569151#M198369</guid>
      <dc:creator>bergen288</dc:creator>
      <dc:date>2021-09-30T13:28:11Z</dc:date>
    </item>
    <item>
      <title>Re: Python script to read Splunk data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Python-script-to-read-Splunk-data/m-p/569173#M198380</link>
      <description>&lt;P&gt;I think that rather than the job.export command, you want job.results command.&amp;nbsp; See&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.2/RESTREF/RESTsearch#search.2Fjobs.2F.7Bsearch_id.7D.2Fresults" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.2/RESTREF/RESTsearch#search.2Fjobs.2F.7Bsearch_id.7D.2Fresults&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2021 15:15:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Python-script-to-read-Splunk-data/m-p/569173#M198380</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-09-30T15:15:26Z</dc:date>
    </item>
    <item>
      <title>Re: Python script to read Splunk data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Python-script-to-read-Splunk-data/m-p/573030#M199730</link>
      <description>&lt;P&gt;My application developer gives me correct Splunk search string (see below), but its output is in&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;lt;class 'collections.OrderedDict'&amp;gt; format which is pretty ugly.&amp;nbsp; Is there a way to define output in CSV format?&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Thanks.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;SEARCH_STRING&lt;/SPAN&gt; &lt;SPAN&gt;=&lt;/SPAN&gt; &lt;SPAN&gt;"""&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; search index=pivotal &amp;nbsp;cf_app_name=ips-challenger-challengerapi-* "*PostPayeeAsync*"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; earliest=-2d latest=-d@d&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; msg.Properties.LoggingTemplate.Exception !="*SubscriberStatus*"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; | eval Message='msg.Properties.LoggingTemplate.Message'&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; | eval SponsorId ='msg.Properties.LoggingTemplate.TenantId'&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; | eval SubscriberId = 'msg.Properties.LoggingTemplate.UserId'&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; | eval Exception = 'msg.Properties.LoggingTemplate.Exception'&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; | eval CorrelationId = 'msg.Properties.LoggingTemplate.AdditionalInformation.CorrelationId'&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; | eval SessionId='msg.Properties.LoggingTemplate.AdditionalInformation.SessionId'&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; | eval PayeeName= 'msg.Properties.LoggingTemplate.AdditionalInformation.PayeeName'&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; | eval Address= 'msg.Properties.LoggingTemplate.AdditionalInformation.Address'&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; | eval MerchantType= 'msg.Properties.LoggingTemplate.AdditionalInformation.MerchantType'&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; | eval MerchantId= 'msg.Properties.LoggingTemplate.AdditionalInformation.MerchantId'&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; | eval AccountNumber= 'msg.Properties.LoggingTemplate.AdditionalInformation.AccountNumber'&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; | sort _time&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; | table _time,SponsorId,SubscriberId,Message,Exception,CorrelationId,SessionId,PayeeName,Address,MerchantType,MerchantId,AccountNumber&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;"""&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 29 Oct 2021 20:34:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Python-script-to-read-Splunk-data/m-p/573030#M199730</guid>
      <dc:creator>bergen288</dc:creator>
      <dc:date>2021-10-29T20:34:58Z</dc:date>
    </item>
    <item>
      <title>Re: Python script to read Splunk data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Python-script-to-read-Splunk-data/m-p/573060#M199739</link>
      <description>&lt;P&gt;The SDK lets you choose the output format.&amp;nbsp; See&amp;nbsp;&lt;A href="https://dev.splunk.com/enterprise/docs/devtools/python/sdk-python/howtousesplunkpython/howtodisplaysearchpython#The-search-results-APIs" target="_blank"&gt;https://dev.splunk.com/enterprise/docs/devtools/python/sdk-python/howtousesplunkpython/howtodisplaysearchpython#The-search-results-APIs&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 30 Oct 2021 12:13:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Python-script-to-read-Splunk-data/m-p/573060#M199739</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-10-30T12:13:03Z</dc:date>
    </item>
    <item>
      <title>Re: Python script to read Splunk data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Python-script-to-read-Splunk-data/m-p/573159#M199772</link>
      <description>&lt;P&gt;I tried both&amp;nbsp;&lt;SPAN&gt;rr = results.ResultsReader(service.jobs.export(SEARCH_STRING, **{"output_mode": "CSV"})) and&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;rr = results.ResultsReader(service.jobs.export(SEARCH_STRING, output_mode="CSV")).&amp;nbsp; Both give me the following invalid format CSV error:&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Traceback (most recent call last):&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; File "e:\Python_Projects\Payees\Code\get_splunk_sdk.py", line 43, in &amp;lt;module&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; rr = results.ResultsReader(service.jobs.export(SEARCH_STRING, **{"output_mode": "CSV"}))&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; File "C:\ProgramData\Anaconda3\lib\site-packages\splunklib\client.py", line 2989, in export&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; return self.post(path_segment="export",&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; File "C:\ProgramData\Anaconda3\lib\site-packages\splunklib\client.py", line 821, in post&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; return self.service.post(path, owner=owner, app=app, sharing=sharing, **query)&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; File "C:\ProgramData\Anaconda3\lib\site-packages\splunklib\binding.py", line 290, in wrapper&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; return request_fun(self, *args, **kwargs)&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; File "C:\ProgramData\Anaconda3\lib\site-packages\splunklib\binding.py", line 71, in new_f&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; val = f(*args, **kwargs)&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; File "C:\ProgramData\Anaconda3\lib\site-packages\splunklib\binding.py", line 764, in post&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; response = self.http.post(path, all_headers, **query)&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; File "C:\ProgramData\Anaconda3\lib\site-packages\splunklib\binding.py", line 1242, in post&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; return self.request(url, message)&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; File "C:\ProgramData\Anaconda3\lib\site-packages\splunklib\binding.py", line 1262, in request&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; raise HTTPError(response)&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;splunklib.binding.HTTPError: HTTP 400 Invalid output mode specified (CSV). -- Invalid output mode specified (CSV).&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&lt;SPAN&gt;If I try the following code:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&lt;SPAN&gt;rr&lt;/SPAN&gt; &lt;SPAN&gt;=&lt;/SPAN&gt; &lt;SPAN&gt;results&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;SPAN&gt;ResultsReader&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN&gt;service&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;SPAN&gt;jobs&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;SPAN&gt;export&lt;/SPAN&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN&gt;SEARCH_STRING&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;output_mode&lt;/SPAN&gt;&lt;SPAN&gt;=&lt;/SPAN&gt;&lt;SPAN&gt;"csv"&lt;/SPAN&gt;&lt;SPAN&gt;))&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;for result in rr:&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; print(result)&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;It seems OK with "rr" statement, but gives me the following error:&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Traceback (most recent call last):&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; File "e:\Python_Projects\Payees\Code\get_splunk_sdk.py", line 47, in &amp;lt;module&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; for result in rr:&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; File "C:\ProgramData\Anaconda3\lib\site-packages\splunklib\results.py", line 210, in next&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; return next(self._gen)&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; File "C:\ProgramData\Anaconda3\lib\site-packages\splunklib\results.py", line 219, in _parse_results&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; for event, elem in et.iterparse(stream, events=('start', 'end')):&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; File "C:\ProgramData\Anaconda3\lib\xml\etree\ElementTree.py", line 1227, in iterator&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; yield from pullparser.read_events()&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; File "C:\ProgramData\Anaconda3\lib\xml\etree\ElementTree.py", line 1302, in read_events&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; raise event&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; File "C:\ProgramData\Anaconda3\lib\xml\etree\ElementTree.py", line 1274, in feed&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; self._parser.feed(data)&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;xml.etree.ElementTree.ParseError: not well-formed (invalid token): line 6, column 101&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;I also tried to add "|&lt;/SPAN&gt;&lt;SPAN&gt;outputcsv myoutput.csv" inside my SEARCH_STRING, I don't know where is its location on Windows Server 2016?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;By the way, your document is pretty hard to understand.&amp;nbsp; Do you mind to give me direct answer next time?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Nov 2021 14:04:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Python-script-to-read-Splunk-data/m-p/573159#M199772</guid>
      <dc:creator>bergen288</dc:creator>
      <dc:date>2021-11-01T14:04:22Z</dc:date>
    </item>
    <item>
      <title>Re: Python script to read Splunk data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Python-script-to-read-Splunk-data/m-p/573164#M199773</link>
      <description>&lt;P&gt;The key question is that the default output in&amp;nbsp;&lt;SPAN&gt;&amp;lt;class 'collections.OrderedDict'&amp;gt; format&amp;nbsp;is ugly and hard to convert to pandas dataframe.&amp;nbsp; The output in CSV format is much easier to load into dataframe.&amp;nbsp; If there is new way to convert output to dataframe, I don't mind what output format it is.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Nov 2021 14:22:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Python-script-to-read-Splunk-data/m-p/573164#M199773</guid>
      <dc:creator>bergen288</dc:creator>
      <dc:date>2021-11-01T14:22:00Z</dc:date>
    </item>
    <item>
      <title>Re: Python script to read Splunk data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Python-script-to-read-Splunk-data/m-p/573169#M199775</link>
      <description>&lt;P&gt;Don't worry, I found a way to load&amp;nbsp;&lt;SPAN&gt;OrderedDict data into dataframe.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Nov 2021 14:39:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Python-script-to-read-Splunk-data/m-p/573169#M199775</guid>
      <dc:creator>bergen288</dc:creator>
      <dc:date>2021-11-01T14:39:10Z</dc:date>
    </item>
  </channel>
</rss>

