Splunk Search

external_lookup.py is missing

chrkohm
Path Finder

Hi,

I'm trying to setup a DNS lookup following the instructions her:

 

https://docs.splunk.com/Documentation/Splunk/8.0.4/Knowledge/Configureexternallookups#External_looku...

 

But there is no external_lookup.py in the $SPLUNK_HOME/etc/system/bin/

Is there a chance to get the external_lookup.py anywhere else?

I´m running Splunk Enterprise 8.0.4 on an SLES 12

Labels (1)
0 Karma
1 Solution

renjith_nair
Legend

@chrkohm,

It's default script shipping with Splunk installation. Unless you manually removed it after the installation, it should be there. 

Try a `find`

 find $SPLUNK_HOME -type f -name "external_lookup.py "

Alternatively you can download a fresh splunk installation and could copy from it

 

 

---
What goes around comes around. If it helps, hit it with Karma 🙂

View solution in original post

renjith_nair
Legend

@chrkohm,

It's default script shipping with Splunk installation. Unless you manually removed it after the installation, it should be there. 

Try a `find`

 find $SPLUNK_HOME -type f -name "external_lookup.py "

Alternatively you can download a fresh splunk installation and could copy from it

 

 

---
What goes around comes around. If it helps, hit it with Karma 🙂
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...