Getting Data In

Why is the Splunk Python SDK not returning formatted numbers in the JSON response?

lpolo
Motivator

Splunk Python SDK does not return formatted numbers in the JSON response.

Example:

|eval var1=tonumber(var2)|
table var1

Results:

[{"var1": "321"}]

I was expecting

[{"var1": 321}]

Any idea why?

Thanks,
Lp

Tags (2)
0 Karma

gwobben
Communicator

I'm not working at Splunk so I can't really answer the why. However, it looks like Splunk is unaware of the data type (which makes sense given that the data type is figured out on search time). I'm guessing this is the reason everything is quoted in the JSON response, to prevent invalid JSON.

It's not very hard to work around this in Python (although there might be a minor performance hit). Try something like this:

def parseDictValues(d):
    for key, value in d.iteritems():

        # Test for a float
        try:
            d[key] = float(value)
        except ValueError:
            pass
    return d

Then loop through the results you've received and call this function to convert all numeric values.

0 Karma

lpolo
Motivator

Splunk should honor that data type in the json response if I specify the data type in the search query.

Thanks,
Lp

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Federated Search for Snowflake Is Now Generally Available on Splunk Cloud Platform

Unlocking Data-In-Place Search Across Splunk and Snowflake  Enterprise data is increasingly distributed across ...

Help Us Build Better Splunk Regex Puzzles (And Win Prizes!)

If you’ve spent any time in the Splunk Community Slack, you’ve likely seen our resident Splunk Trust ...

Fuel Your Journey: What’s Waiting for You at the .conf26 Acceleration Station

Navigating the show floor at .conf26 isn't just about keynotes and technical breakout sessions; it's also ...