Getting Data In

Splunk add-on save checkpoint

nareshkumarg
Path Finder

Hi All,

I managed to store and retrieve data using the following python command.

 # save checkpoint
 helper.save_check_point(key, state)
 # delete checkpoint
 helper.delete_check_point(key)
 # get checkpoint
 state = helper.get_check_point(key)

I would like to know where the data is stored and how can I check the value on Splunk.

I was checking under lookup with the name and source given for the add-on I was working on, but could not find it.

Regards,
Naresh

0 Karma
1 Solution

harsmarvania57
Ultra Champion

Hi,

Usually checkpoint stored in $SPLUNK_HOME/var/lib/splunk/modinputs/<some_name_provided_by_developer>/ , it looks like you are asking about Palo-Alto add-on.

View solution in original post

harsmarvania57
Ultra Champion

Hi,

Usually checkpoint stored in $SPLUNK_HOME/var/lib/splunk/modinputs/<some_name_provided_by_developer>/ , it looks like you are asking about Palo-Alto add-on.

nareshkumarg
Path Finder

Thanks a lot @harsmarvania57 I was able to find the value which was stored with base64.

0 Karma

nareshkumarg
Path Finder

I have developed my own add on and I want to check the value to validate the functioning of my python script.

0 Karma

harsmarvania57
Ultra Champion

Have you looked at the path which I have provided? If you can't find it then you need to provide your full python code (Hide sensitive data).

0 Karma
Get Updates on the Splunk Community!

Get More Out of Your Security Practice With a SIEM

Get More Out of Your Security Practice With a SIEMWednesday, July 31, 2024  |  11AM PT / 2PM ETREGISTER ...

New This Month - SLO Capabilities, APM Advanced Filtering & Usage Analytics Plus ...

More for SLO Management We’re continuing to expand the built-in SLO management experience in Splunk ...

Enterprise Security Content Update (ESCU) | New Releases

In June, the Splunk Threat Research Team had 2 releases of new security content via the Enterprise Security ...