Splunk Dev

Why did external search command exit unexpectedly with non-zero error code 1?

medveleyenet
New Member

Hi
I create a script whit python and i configure the commands.conf but appears the follow message: "External search command exited unexpectedly with non-zero error code 1"

commands.conf
[sshprueba8]
chunked = true
filename = sshprueba8.py

script

!/usr/bin/env python

-- coding: utf-8 --

import paramiko
import sys
import time
HOST = "172.16.10.100"
USER = "admin"
PASS = "admin"
ITERATION = 1

f = open ('/Documents/Archivo de prueba.txt','w')

def fn():
client1=paramiko.SSHClient()
client1.set_missing_host_key_policy(paramiko.AutoAddPolicy())
client1.connect(HOST,username=USER,password=PASS)
stdin, stdout, stderr = client1.exec_command('show ip interface brief')
saveoutput = open("/Users/RicardoMedina/Documents/Archivo de prueba.txt", "a")
saveoutput.write(stdout.read())
print stdout.read()
fn()

0 Karma

splunkoptimus
Path Finder
0 Karma

lguinn2
Legend

Does this script run properly when used independently of Splunk?
Does this script run properly when using the same account as Splunk?

Splunk has its own copy of python which it will use to execute scripts. Does the Splunk python have the libraries that you need?

Did you look at the search.log that was created when you tried to use this command?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Vibe-coding, AI, and Splunkcraft: Highlights from the .conf26 Builder Bar

If you stopped by the Builder Bar at .conf26, thank you! This year, we brought ...

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...