Splunk Dev

Python script. Module not loading when executed by splunk

ryan461
Explorer

I have a python script on our splunk server to ingest data from a database using pymssql and _mssql. I added this script through the web gui in Manager > Data Inputs > Scripts. I can run the script manually just fine. But when its executed by splunk, in the splunkd logs it says ImportError: No module named _mssql.

The pymssql/_mssql package was installed manually.

Tags (1)
1 Solution

alacercogitatus
SplunkTrust
SplunkTrust

Splunk uses it's own python to execute scripts. So if Splunk Python doesn't know about _mssql, it won't find it. Did you install _mssql to the file system? Try running manually with splunk cmd python /path/to/your/script. I got around that by using a sh script to call the python script with #!/usr/bin/python as the executable to use.

View solution in original post

asifhj
Path Finder

Guys,

Instead setting all those parameters and creating subproccess.
Simply copy your required packages/files from


/usr/local/lib/python2.7/dist-packages

to

/opt/splunk/lib/python2.7/site-packages/


David
Splunk Employee
Splunk Employee

I downvoted this post because this is not supported, and as a comment suggested, will break between upgrades (and also not be transferrable between systems)

0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

Possible, but if you upgrade, you may lose the files.

0 Karma

dalglish
New Member

I just use wrapper python script with non-splunk python with installed modules in scripted input. (taken from here) Something like that:

import os, sys
for envvar in ("PYTHONPATH", "LD_LIBRARY_PATH"):
    if envvar in os.environ:
        del os.environ[envvar]
python_executable = "D:\Python27\python.exe"
real_script = "path_to_script"
os.execv(python_executable, [ python_executable, real_script ] + sys.argv[1:])
0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

Splunk uses it's own python to execute scripts. So if Splunk Python doesn't know about _mssql, it won't find it. Did you install _mssql to the file system? Try running manually with splunk cmd python /path/to/your/script. I got around that by using a sh script to call the python script with #!/usr/bin/python as the executable to use.

alacercogitatus
SplunkTrust
SplunkTrust

You could, but I just use the python print command, and splunk eats it just fine. I used the exec command from the sh script and it works great.

0 Karma

ryan461
Explorer

That does get it to execute, the data being ingested was being printed, which splunk would read. But now that its a shell script executing it, i imagine ill have to write to a file or something?

0 Karma
Get Updates on the Splunk Community!

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...