Splunk Search

external_lookup.py is missing

chrkohm
Explorer

Hi,

I'm trying to setup a DNS lookup following the instructions her:

 

https://docs.splunk.com/Documentation/Splunk/8.0.4/Knowledge/Configureexternallookups#External_looku...

 

But there is no external_lookup.py in the $SPLUNK_HOME/etc/system/bin/

Is there a chance to get the external_lookup.py anywhere else?

I´m running Splunk Enterprise 8.0.4 on an SLES 12

Labels (1)
0 Karma
1 Solution

renjith_nair
SplunkTrust
SplunkTrust

@chrkohm,

It's default script shipping with Splunk installation. Unless you manually removed it after the installation, it should be there. 

Try a `find`

 find $SPLUNK_HOME -type f -name "external_lookup.py "

Alternatively you can download a fresh splunk installation and could copy from it

 

 

View solution in original post

renjith_nair
SplunkTrust
SplunkTrust

@chrkohm,

It's default script shipping with Splunk installation. Unless you manually removed it after the installation, it should be there. 

Try a `find`

 find $SPLUNK_HOME -type f -name "external_lookup.py "

Alternatively you can download a fresh splunk installation and could copy from it

 

 

View solution in original post

Register for .conf21 Now! Go Vegas or Go Virtual!

How will you .conf21? You decide! Go in-person in Las Vegas, 10/18-10/21, or go online with .conf21 Virtual, 10/19-10/20.