I did * | geoip clientip
yet I get an error:
"External search command 'geoip' returned error code 1. First 1000 (of 9218) bytes of script output:" followed by the script output.
A screenshot is here:
You can do:
* | geoip clientip
This will pipe all events in the index into the geoip tool.
Looks like you're getting an exception that splunk doesn't know how to parse. The main thing is it's returning failure (a nonzero exit code). You may want to capture from inside the script how it's being invoked and run it independently to investigate.
You can do:
* | geoip clientip
This will pipe all events in the index into the geoip tool.
Hmm. I don't think that screenshot tells us much as to what the error is. There should be a python.log in $SPLUNK_HOME/var/log/splunk/ That should have the full error message.
@ftk I've updated the question with an error, any help?