Installation

howto install and use Splunk python sdk on Windows

coenvandijk
Observer

I'm trying to create a custom search called acltranslate in Splunk on Windows

When running the search I get an error:
Error in 'acltranslate' command: External search command exited unexpectedly with non-zero error code 1.

The log files contains:
08-17-2017 10:18:36.505 INFO ChunkedExternProcessor - Running process: "C:\Program Files\Splunk\bin\python.exe" "C:\Program Files\Splunk\etc\apps\pggm_TA_Windows\bin\acltranslate.py"
08-17-2017 10:18:36.539 ERROR ChunkedExternProcessor - EOF while attempting to read transport header
08-17-2017 10:18:36.540 ERROR ChunkedExternProcessor - Error in 'acltranslate' command: External search command exited unexpectedly with non-zero error code 1.
08-17-2017 10:18:36.540 INFO UserManager - Unwound user context: dijc -> NULL
08-17-2017 10:18:36.543 ERROR ChunkedExternProcessor - stderr: Traceback (most recent call last):
08-17-2017 10:18:36.543 ERROR ChunkedExternProcessor - stderr: File "C:\Program Files\Splunk\etc\apps\pggm_TA_Windows\bin\acltranslate.py", line 2, in
08-17-2017 10:18:36.543 ERROR ChunkedExternProcessor - stderr: from splunklib.searchcommands import dispatch, StreamingCommand, Configuration
08-17-2017 10:18:36.543 ERROR ChunkedExternProcessor - stderr: ImportError: No module named splunklib.searchcommands

Clearly python is unable to find the SDK.

How can I install the python sdk on Windows? All the docmentation I can find seems to be related to Unix/Linux variants. The official documentation provided with the SDK does not mention how to install the sdk on Windows

Tags (1)
0 Karma

rvany
Communicator

You have to add your splunk-lib-directory to the python path. I'm not sure if this doc is still current but it may be worth have a look on:

http://www.linuxtopia.org/online_books/programming_books/python_programming/python_ch28s04.html

0 Karma
Get Updates on the Splunk Community!

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureThursday, March 27, 2025  |  11AM PST / 2PM EST | Register NowStep boldly ...

Splunk AppDynamics with Cisco Secure Application

Web applications unfortunately present a target rich environment for security vulnerabilities and attacks. ...