Hello everyone, i would like to ask if you guys have an idea on how can i send the data i got from splunk to python arguments? I have a splunk search that will determine the data and call/trigger the python script that have an arguments.
would really appreciate your help. thank you.
You could create an alert that runs a script with either the deprecated approach or the new approach. I don't believe you can pass arguments directly to that script. But if your arguments are in the search results, parse them out in the alert script and then call the actual script from there.
Or if you don't need/want to call the script based on some alert trigger, you could use spunk's rest api to just run a search, then parse the results, then call your script
Not sure if any of that helps, but hopefully at least points you in the right direction.