Splunk Search

External command configured automatic

rdownie
Communicator

I wrote an external command to just adjust the timezone and reformat _time and return a new field. It is a very simple python script. I want it to run automatically against a specific sourcetype. I can see you can do it with an external lookup or a lookup. Can I have this run for an external command? I have tried to do it but it does not appear to work. If I put the command inline in the search, it works fine.
Any help would be appreciated.
-Bob

0 Karma

jplumsdaine22
Influencer

Have a look at the external_cmd configuration in transforms.conf http://docs.splunk.com/Documentation/Splunk/latest/Admin/Transformsconf

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...