Getting Data In

How to execute a py or sh by interface of Splunk

Lindaiyu
Path Finder

Hello,

I write a xxx.sh in the /splunk/etc/apps/my_apps/bin and by the commande line

./xxx.sh

to execute the code.

Could I add a bouton or something else in the interface of my app in Splunk
alt text

to trigger the xxx.sh.

Thank you very much
Hanzhi

0 Karma

vinitatsky
Communicator

http://answers.splunk.com/answers/25658/whats-the-point-of-custom-python-scripts.html

This is what I did
Put my custom python script in this folder
/var/sky/splunk/etc/system/bin

import csv
import sys
import splunk.Intersplunk
import string
(isgetinfo, sys.argv) = splunk.Intersplunk.isGetInfo(sys.argv)
if len(sys.argv) < 2:
splunk.Intersplunk.parseError("No arguments provided to custom script")

results = splunk.Intersplunk.readResults(None, None, True)
splunk.Intersplunk.outputResults(results)

Modify commands.conf file in below folder
/var/sky/splunk/etc/system/local

defaults for all external commands, exceptions are below in individual stanzas

type of script: 'python', 'perl'

TYPE = python

default FILENAME would be .py for python, .pl for perl and otherwise

is command streamable?

STREAMING = true

maximum data that can be passed to command (0 = no limit)

MAXINPUTS = 50000

end defaults

[customtest]
filename = customtest.py

To reload the setting run this URL in your browser (Just in case, if required)
https://SPLUNK_HOSTNAME:PORT/debug/refresh

And this is how we can use custom command in splunk
| customtest GETINFO [Inputparameters]

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...