Splunk Dev

Question regarding SPLUNK_ARG_8/ Difficulty in writing python script for alert

Chinmai
Explorer

Hello Guys,

I have demo.csv file which is being continuously monitored, this file contains 3 fields namely servername, jobname and status.
This demo file is continuously being updated by another script.
Demo file contents are like this

servename,jobname,status
aaa, xyz1, success
bbb, xyz2, success
aaa, xyz3, fail.

Now i am monitoring the status of the jobs via splunk, so i have created a alert which will trigger and send a mail, whenever a job fails. The mail contains table format output of search query which has servename, jobname and status columns.

Now i am writing a python script which will be invoked by this alert along with the mail. So this python will update the status of respective job from "fail" to "success" in the demo.csv file.

But it seems my python script is not working, can anyone help me to write this python script?

Thanks in advance.

Tags (1)
0 Karma

mattymo
Splunk Employee
Splunk Employee

Splunk professional services would be glad to help you!! 😉
https://www.splunk.com/en_us/support-and-services/professional-services.html

Perhaps you can share your current code on github and someone might have a look?

In the meantime, I would recommend checking out some of the alert actions in splunkbase and reviewing their code as well as the alert action framework.

In your question you refer to the deprecated "run a script" alert actions, that still works, but you are much better off building for the alert action framework.

https://splunkbase.splunk.com/apps/#/app_content/alert_actions

http://docs.splunk.com/Documentation/Splunk/6.6.1/AdvancedDev/ModAlertsIntro
https://www.splunk.com/blog/2016/08/22/how-to-create-a-modular-alert.html
http://dev.splunk.com/view/dev-guide/SP-CAAAE7A

What you are trying to do sounds pretty simple...almost makes me wonder if an outputlookup or kvstore might not be easier?

- MattyMo
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...