Splunk Search

Why custom search command not working without being prefixed by dedup

Cristian
Observer

Hi,

I created a custom StreamingCommand which makes REST API calls to get user details, based on a userid.

If command is executed as below, it is working as expected

 

index="<hidden_index>" <hidden_filters> | dedup jobFields.user | getuserdetails fields="Division,FullName" userid=jobFields.user 

 

 If I remove the "dedup ..." then the command crashes:

 

index="<hidden_index>" <hidden_filters> | getuserdetails fields="Division,FullName" userid=jobFields.user 

Error: 
[hidden_index_server]Streamed search execute failed because: Error in 'getuserdetails' command: External search command exited unexpectedly with non-zero error code 1..

 

 

The stream method code is below:

 

def stream(self, records):
        for record in records:
            try:
                result = self.getUserDetails(record[self.userid])
                self.log(topic='STREAM', value=result)
                for field in self.fields:
                    if field in result:
                        record[field] = result[field]
                yield record
            except (Exception) as e:
                template = "An exception of type {0} occurred. Arguments:\n{1!r}"
                message = template.format(type(e).__name__, e.args)
                self.log(topic='ERROR', value=message)
        try:
            #update cache details for later use
            self.cachedDetails.updateCache()
        except (Exception) as e:
                template = "An exception of type {0} occurred. Arguments:\n{1!r}"
                message = template.format(type(e).__name__, e.args)
                self.log(topic='ERROR', value=message)

 

 

 

The only reason I needed dedup was because I wanted to save the API calls but now I have a cache and I do not need to do this anymore.

Somehow the error seem to come from the indexers. We have 12 indexers and I get 12 error, 1 for each indexer.

I tried with "localop" but while the errors disappeared,  this is too slow to even consider having it in production.

Any suggestion?

 

Thanks,

Cristian

Labels (1)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Everything Community at .conf24!

You may have seen mention of the .conf Community Zone 'round these parts and found yourself wondering what ...

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...