Splunk Dev

Why am I getting this error "External search command 'File_Move1' returned error code 1" every time I run my python script?

Vipun
Explorer

• I am trying to execute python script File_Move1 using the search query |script File_Move1 but received the error below:
External search command 'File_Move1' returned error code 1.

• Please find my commands.conf details below in my C:\Program Files\Splunk\etc\system\local

[File_Move1]
chunked = true
filename = File_Move1.py
type = python

• I have placed the file in bin directory of C:\Program Files\Splunk\etc\apps\search\bin\scripts and C:\Program Files\Splunk\bin\scripts but still I receive that error
• I was able to execute the same script using Splunk cmd python File_Move.py using command prompt.

I kindly request you to look into it and guide me how to get rid of that error. I really appreciate your help on this.

Labels (1)

493669
Super Champion

Try running below:

< search query>| script python File_Move1.py 

Refer:https://answers.splunk.com/answers/62473/how-to-execute-external-script-to-manipulate-file-from-sear...

0 Karma

Vipun
Explorer

Hi,

Thank you for the help on this.

I have tried index="test" | script python File_Move1 or index="test" | script python File_Move1.py
earlier but still no luck. Could you please advise with any other fix.

highsplunker
Contributor

hi Vipun. i have the same error message -- i'm playing with Splunk REST API functionality now. i think you have to dig the script itself first.
in my case there was simply a syntactic error in my python code.
don't give up, good luck 🙂

0 Karma

Vipun
Explorer

Hi 493669,

I have followed that earlier but still, I get the same error

index="test" | script python File_Move1.py 

or

index="test" | script python File_Move1

⚠ External search command 'File_Move1' returned error code 1.
Please suggest any answers. Thank you for the help!!

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...