Splunk Enterprise

How do I handle multivalues by splunk custom search command under Search Command Protocol version 2.

Ultra Champion


I want to make this with SCPversion2, but it doesn't work.

my code:


#!/usr/bin/env python

import sys
from splunklib.searchcommands import dispatch, StreamingCommand, Configuration, Option, validators

class mvsortCommand(StreamingCommand):
    """ sort multivalue

    def stream(self, records):
        self.logger.debug('mvsortCommand: %s', self)  # logs command line

        for record in records:
            if isinstance(record[self.fieldnames[0]],(str)):

            yield record

dispatch(mvsortCommand, sys.argv, sys.stdin, sys.stdout, __name__)


I think I'm not handling generators and lists correctly, but I'm not sure.
Is there a good example?

Labels (1)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

Database Performance Sidebar Panel Now on APM Database Query Performance & Service ...

We’ve streamlined the troubleshooting experience for database-related service issues by adding a database ...

IM Landing Page Filter - Now Available

We’ve added the capability for you to filter across the summary details on the main Infrastructure Monitoring ...

Dynamic Links from Alerts to IM Navigators - New in Observability Cloud

Splunk continues to improve the troubleshooting experience in Observability Cloud with this latest enhancement ...