Alerting

Python Alert Script not running when using pyodbc

bruceclarke
Contributor

All,

I ran into an issue with my python alert script after trying to import pyodbc into my script. I read elsewhere that it might be due to Splunk's version of python not being able to import pyodbc. So, I created a wrapper python script as described here: http://answers.splunk.com/answers/10839/scripted-lookup-script-doesnt-work-with-splunk-python-versio....

When I run

splunk cmd python "path/to/python/wrapper"
everything works fine. I see the output and it sends an email as I expected. However, when the alert gets triggered by Splunk, the script fails. I see the following error in splunkd.log:

02-11-2014 20:04:05.573 -0500 WARN  script - Maxinputs must be at least 10000, command name="runshellscript"

Any ideas on how to fix this? Thanks!

Tags (3)
0 Karma
1 Solution

bruceclarke
Contributor

There were two versions of python on the machine. This led to a conflict that was masked by a hard to decipher error message in Splunk.

View solution in original post

0 Karma

bruceclarke
Contributor

There were two versions of python on the machine. This led to a conflict that was masked by a hard to decipher error message in Splunk.

0 Karma

bruceclarke
Contributor

Oh, and just to be clear, the script runs fine if I remove the reference to pyodbc and skip my table lookup (ultimately, though, I need to make this call).

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Quantify Your Splunk Investment Impact: Introducing Savings Metrics to Value Insights

Building on the foundation established in our initial Value Insights releases, we are introducing the Savings ...

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...