Splunk Dev

Custom Python Command to read a CSV file

marvinlee93
Explorer

I have created a custom python command but I'm facing this problem. I have a dynamic fileName.
The filename that I want to read changes everyday.
It works fine before I package the code using the splunk streaming command.

with open('C:\Users\Desktop\%s\%s\%s'%('assetfiles','DailySchedule',fileName)) as csv_file:
This will give me:
C:\Users\KGQJ3999\Desktop\assetfiles\assetfiles\DailySchedule\2019-12-20_NAME1.csv

However, after packaging it into the streaming command, it's giving me this.
C:\Users\KGQJ3999\Desktop\assetfiles\assetfiles\DailySchedule\ .csv

I have tried many ways to concatenate strings. Even forcing the filename to be str(fileName). Still, the fileName is dissappearing from the splunk side and I'm getting the IO error.

Anybody has any idea why??

Labels (1)
0 Karma

martynoconnor
Communicator

Is fileName a field that exists in your search results immediately before you | to your custom command? If not, I would have expected the script to error out (missing a required arg?) but perhaps it's carrying on with null/empty value and that's why you're getting a csv with no name?

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...