Splunk Search

Is it possible to use ".exe" as an External Lookup?



Is it possible to use ".exe" as an External Lookup?

Everything I make a lookup in a search I receive the following errors:
- Error in 'lookup' command: The lookup table 'goredislookup' does not exist or is not available.
- LookupOperator - Could not find 'redislookup.exe'. It is required for lookup 'goredislookup'.



0 Karma


As the UI says in the define lookup screen "Specify the command and arguments to invoke to perform lookups. The command must be a Python script located in $SPLUNK_HOME/etc/apps/app_name/bin or $SPLUNK_HOME/etc/searchscripts."

You could just make a python wrapper that calls an exe - have a look here for starters https://docs.python.org/2/library/subprocess.html#using-the-subprocess-module or just have a look on stackoverflow

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!