Splunk Search

Why am I getting "Error in 'disabler' command: The external search command 'disabler' does not exist in commands.conf"?

annalisefolsen
Explorer

I have an app for a custom command called disabler and I am trying to call the command by:

... | disabler | ...

But I keep getting the error message:

Error in 'disabler' command: The external search command 'disabler' does not exist in commands.conf.

I have placed the commands.conf file in both the default and local folders and have restarted Splunk, but the results are always the same. This is my commands.conf file:

[disabler]
filename = splunkProgram.py
generating = true
local = true
maxinput = 0
0 Karma
1 Solution

annalisefolsen
Explorer

Okay, I have fixed this. This has the best explanations for setting up an app. I was told in other posts that logging.conf was optional, but apparently it is not. This should help anyone looking to answer this http://blogs.splunk.com/2014/04/14/building-custom-search-commands-in-python-part-i-a-simple-generat...

View solution in original post

annalisefolsen
Explorer

Okay, I have fixed this. This has the best explanations for setting up an app. I was told in other posts that logging.conf was optional, but apparently it is not. This should help anyone looking to answer this http://blogs.splunk.com/2014/04/14/building-custom-search-commands-in-python-part-i-a-simple-generat...

Get Updates on the Splunk Community!

Infographic provides the TL;DR for the 2024 Splunk Career Impact Report

We’ve been buzzing with excitement about the recent validation of Splunk Education! The 2024 Splunk Career ...

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...