Installation

Python script execution from Splunk GUI

manish_singh_77
Builder

Hi Team,

We have a python script which runs and executes the results of the knowledge objects of rest apis. We are going to run this script on adhoc basis which will modify and list the permissions. Do we have to use custom search command for that?

If yes then please let us know the approach...

Tags (1)
0 Karma

manjunathmeti
Champion

You can create a custom alert action to trigger python script using steps provided here:

https://answers.splunk.com/answers/810829/problem-with-scripted-alert.html#answer-810832

And use sendalert command to trigger script.

<base search> | sendalert scriptcustomalert
0 Karma

manish_singh_77
Builder

@manjunathmeti ,

I have a python script, for now I am executing the commands from the server and getting the results.

For example: /opt/splunk/bin/splunk cmd python /home/splunk/test_Script.py list savedsearch --user test_user

This will return the results once executed from the server, how we do the same thing from GUI?

0 Karma

manjunathmeti
Champion

If you want to run a script as command and get results in search app then you need to create a custom search command. Check this:

https://dev.splunk.com/enterprise/docs/developapps/customsearchcommands/createcustomsearchcmd

If you listing all saved searches, you can use below search query:

| rest /servicesNS/-/-/saved/searches  | table title,cron_schedule,next_scheduled_time,eai:acl.owner,actions,eai:acl.app
0 Karma

manish_singh_77
Builder

@manjunathmeti

Thanks for your reply, slight correction from my end, we can also use curl utility to modify the permissions, right?

0 Karma

manjunathmeti
Champion

If you are asking about modifying the splunk objects (like savedsearches, views etc.) permissions using REST API calls using curl utility, then yes you can use that.

Check this link:
https://docs.splunk.com/Documentation/Splunk/8.0.3/RESTTUT/RESTbasicexamples

0 Karma

manish_singh_77
Builder

@manjunathmeti

Do you have any sample python script?

0 Karma
Get Updates on the Splunk Community!

Fueling your curiosity with new Splunk ILT and eLearning courses

At Splunk Education, we’re driven by curiosity—both ours and yours! That’s why we’re committed to delivering ...

Splunk AI Assistant for SPL 1.1.0 | Now Personalized to Your Environment for Greater ...

Splunk AI Assistant for SPL has transformed how users interact with Splunk, making it easier than ever to ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureOn Demand Now Step boldly into the AI revolution with enhanced security ...