I am trying to implement EventingCommand interface, and return just one custom event at the end of processing multiple events in Splunk. I have the code written in Python and integrated. But for some reason, the code returns multiple events in Splunk.
Can someone point out what is the problem here?
import sys from splunklib.searchcommands
import dispatch, EventingCommand, Configuration
@Configuration()
class testpython(EventingCommand):
def transform(self, records):
list1 =[{'count': 1}]
return list1
if __name__ == "__main__": dispatch(testpython, sys.argv, sys.stdin, sys.stdout, __name__)