Getting Data In

Splunk add-on save checkpoint

nareshkumarg
Path Finder

Hi All,

I managed to store and retrieve data using the following python command.

 # save checkpoint
 helper.save_check_point(key, state)
 # delete checkpoint
 helper.delete_check_point(key)
 # get checkpoint
 state = helper.get_check_point(key)

I would like to know where the data is stored and how can I check the value on Splunk.

I was checking under lookup with the name and source given for the add-on I was working on, but could not find it.

Regards,
Naresh

0 Karma
1 Solution

harsmarvania57
Ultra Champion

Hi,

Usually checkpoint stored in $SPLUNK_HOME/var/lib/splunk/modinputs/<some_name_provided_by_developer>/ , it looks like you are asking about Palo-Alto add-on.

View solution in original post

harsmarvania57
Ultra Champion

Hi,

Usually checkpoint stored in $SPLUNK_HOME/var/lib/splunk/modinputs/<some_name_provided_by_developer>/ , it looks like you are asking about Palo-Alto add-on.

nareshkumarg
Path Finder

Thanks a lot @harsmarvania57 I was able to find the value which was stored with base64.

0 Karma

nareshkumarg
Path Finder

I have developed my own add on and I want to check the value to validate the functioning of my python script.

0 Karma

harsmarvania57
Ultra Champion

Have you looked at the path which I have provided? If you can't find it then you need to provide your full python code (Hide sensitive data).

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...