Hi,
Im trying to add data to the index through Splunk Python SDK . Here .py file is executed successfully but no events found inside the index
Here are my code
import splunklib.client as client
import sys,os
import socket
............................
service = client.connect(
host=HOST,
port=PORT,
username=USERNAME,
password=PASSWORD,
owner=OWNER,
app=APP)
myindex = service.indexes.create("test_index2")
#sock.send("Test event\r\n")
mysocket = myindex.attach()
mysocket.send("This is my socket event\r\n")
mysocket.close()
Code Type 2 :
import splunklib.client as client
import sys,os
.................................
service = client.connect(
host=HOST,
port=PORT,
username=USERNAME,
password=PASSWORD,
owner=OWNER,
app=APP)
myindex.submit('This is my HTTP event',sourcetype='test', host='localhost')
Please verify and let me know what changes i have to do?
just checked without owner=OWNER,,app=APP . below code worked
service = client.connect(
host=HOST,
port=PORT,
username=USERNAME,
password=PASSWORD)
myindex.submit('This is my HTTP event',sourcetype='test', host='localhost')
need to investigate it...
How about if there is long string, such as "37.31.31.31 - - [13/Dec/2015:23:08:40 +0100] ""POST /administrator/index.php HTTP/1.1"" 200 4494 """ ""Mozilla/5.0 (Windows NT 6.0; rv:34.0) Gecko/20100101 Firefox/34.0"" ""-""" Somehow it ignores it...
The problem is about ": : : ". How to fix it????