Monitoring Splunk

coldToFrozenScript arguments

m22oswald
Engager

In the coldToFrozenExample.py script there is a --search-files-required argument switch that it looks for, and if found will archive additional files instead of deleting them.

I don't want to use this, but I would like to add my own switch to the script in order to add make it more widely applicable.  However, I'm not sure how to actually call the script with the arguments.  Here is the line from indexes.conf that specifies the script:

 

 

 

 

coldToFrozenScript = "$SPLUNK_HOME/bin/python" "$SPLUNK_HOME/bin/scripts/coldToFrozen.py"

 

 

 

 

When Splunk actually makes the call, it automatically inserts the bucket to archive after the script name (it has to do this, because the script searches for the bucket name as the first argument).  So I don't know how I would specify a second argument.

If anyone can point me in the right direction, I would very much appreciate it.  Thanks so much. 

 

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Unless you can get a job as a programmer at Splunk and change the code, you're stuck with the calling sequence described in the Admin manual for coldToFrozenScript  at https://docs.splunk.com/Documentation/Splunk/8.2.4/Admin/Indexesconf

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Unless you can get a job as a programmer at Splunk and change the code, you're stuck with the calling sequence described in the Admin manual for coldToFrozenScript  at https://docs.splunk.com/Documentation/Splunk/8.2.4/Admin/Indexesconf

---
If this reply helps you, Karma would be appreciated.
0 Karma

m22oswald
Engager

I figured that would be the answer, but still a little disappointed.  Thanks for the quick reply

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Consider making your case for an enhancement at https://ideas.splunk.com

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...