Splunk Dev

How do you pass saved search parameters to a Python script?

andrei1bc
Communicator

Hi,

I am trying to pass arguments from a savedsearch result to a python script, and it does not work. Code below.

savedsearches.conf

[test_search]
action.log_message = 1
action.log_message.param.name = $name$
action.log_message.param.condition = $result.condition$
action.log_message.param.host = $result.host$
action.log_message.param.source = $result.source$
alert.digest_mode = 0
alert.suppress = 0
alert.track = 1
counttype = number of events
cron_schedule = */1 * * * *
disabled = 1
dispatch.earliest_time = -5m
dispatch.latest_time = now
enableSched = 1
quantity = 0
relation = greater than
request.ui_dispatch_app = search
request.ui_dispatch_view = search
search = index=main host=test_host source=test_source status=* earliest=-2m latest=now | eval condition=if(status!="OK","CRITICAL","OK") | stats last(condition) as condition by host,source

alert_actions.conf

[log_message]
is_custom = 1
label = test
description = test
icon_path = appIcon.png
alert.execute.cmd = test.py
payload_format = json
disabled = 0
param.name = 
param.condition = 
param.host = 
param.source = 

test.py

#!/bin/python
import json
import sys
import os
import datetime

timestamp = datetime.datetime.utcnow().strftime("%Y-%m-%dT%H:%M:%SZ")

name = config['name']
condition = config['condition']
host = config['host']
source = config['source']

f = open('temp.txt', 'w')
sys.stdout = f
sys.stderr = f
print(host, source, name, condition, timestamp)
f.close()

And I get no output. If hard code some values in the script directly, then the file will be written every time the script is triggered.

Expected output

('test_host', 'test_source', 'test_search', 'condition' , 'timestamp')

Thank you in advance.

Regards,

Labels (2)
0 Karma

koshyk
Super Champion

As you might be aware , there will be 9 fields Splunk arguments you can get for alerting purposes
https://docs.splunk.com/Documentation/Splunk/latest/Alert/Configuringscriptedalerts

For debugging, you could print all these 9 fields out into an output and see if it is useful. There is a quite old Splunk to Tivoli script, you can see if useful. The SPLUNK_ARG_8 will give you the file in which the results for the search are stored, which you can stream out using your python script.

Also are you using Splunk's python to trigger your python script?

0 Karma

vasanthi77
Explorer

were you able to resolve this? I have similar requirement, need some help.

0 Karma
Get Updates on the Splunk Community!

Updated Data Type Articles, Anniversary Celebrations, and More on Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

A Prelude to .conf25: Your Guide to Splunk University

Heading to Boston this September for .conf25? Get a jumpstart by arriving a few days early for Splunk ...

4 Ways the Splunk Community Helps You Prepare for .conf25

.conf25 is right around the corner, and whether you’re a first-time attendee or a seasoned Splunker, the ...