Splunk Search

How to get the json results of my custom script in Splunk?

rockzers
Path Finder

i created a custom python api script and it works fine and i want to import in splunk

so i put my script. "C:\\Program Files\\Splunk\\etc\\apps\\search\\bin\\sample.py"

I run cmd and the result is getting correctly

in splunk i created data inputs -> scripts -> select my scripts -> select source type _json -> app context App Browser -> selected index

but i am not getting any json results in splunk search index

Is there any configuration needed?

when i check input.config it is already correctly the file details, so why splunk index doesn't show any json data?

[script://$SPLUNK_HOME\etc\apps\search\bin\sample.py]
disabled = false 
host = home 
index = jsearch 
interval = 60.0 
sourcetype = _json   
Tags (3)
0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@rockzers - Try updating the stanza name to:

[script://$SPLUNK_HOME/etc/apps/search/bin/sample.py]

 

I hope this helps!!!

0 Karma

rockzers
Path Finder

@VatsalJagani 

i used windows so that stanza is there 

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@rockzers - Okay.

Do you see the input when you open Splunk Web UI and Go to "Settings > Inputs"?

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...