Splunk Search

elasticsplunk convert to python3 not working- do you have an alternative suggestion?

jinnypt
Explorer

Hello.

Up to Splunk 7 version, it was python2, so I was using the app below to search elasticsearch.

https://github.com/brunotm/elasticsplunk

 

As I upgraded the Splunk version to 8 and started using python3, the app could not run.

So, I ask if there is a way to use this app.

* How to use it in python3? (If the conversion is successful and is in use, can you share it?)

* Is there an app that can replace it? (I'm not going to use the Elasticsearch Data Integrator - Modular Input app.)

* If there is an app you are using with splunk 8 (python3), please recommend it.

0 Karma
1 Solution

jinnypt
Explorer

I solved it!

 

I added the path and file below.

 

$SPLUNK_HOME/etc/apps/{application_name}/local/server.conf

[general]

python.version = python2

View solution in original post

jinnypt
Explorer

Temporarily solved it with the method below.

 

$SPLUNK_HOME/etc/system/local/server.conf

[general]

python.version = python2

 

Since the above method runs in python2 for all apps, I think it will cause problems in the future.

Is there a way to run only a specific app with python2?

 

Entering the settings below doesn't work in python2.

$SPLUNK_HOME/etc/apps/{application_name}/local/app.conf

[install]

python.version = python2

0 Karma

jinnypt
Explorer

I solved it!

 

I added the path and file below.

 

$SPLUNK_HOME/etc/apps/{application_name}/local/server.conf

[general]

python.version = python2

splunkcol
Builder

@jinnypt 

Hello,

I have noticed that the Elasticsplunk app no longer exists https://splunkbase.splunk.com/app/3493 I do not know if you know what the reason is or if it was updated by another APP I would appreciate if you could inform me.

At this moment I need to use that APP or the one that allows me to use the query with the "ess" command.

If possible it would help me a lot which are the configuration files that I have to modify both on splunk and Elasticsearch side.

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...