Splunk Search

external_lookup.py is missing

chrkohm
Path Finder

Hi,

I'm trying to setup a DNS lookup following the instructions her:

 

https://docs.splunk.com/Documentation/Splunk/8.0.4/Knowledge/Configureexternallookups#External_looku...

 

But there is no external_lookup.py in the $SPLUNK_HOME/etc/system/bin/

Is there a chance to get the external_lookup.py anywhere else?

I´m running Splunk Enterprise 8.0.4 on an SLES 12

Labels (1)
0 Karma
1 Solution

renjith_nair
Legend

@chrkohm,

It's default script shipping with Splunk installation. Unless you manually removed it after the installation, it should be there. 

Try a `find`

 find $SPLUNK_HOME -type f -name "external_lookup.py "

Alternatively you can download a fresh splunk installation and could copy from it

 

 

---
What goes around comes around. If it helps, hit it with Karma 🙂

View solution in original post

renjith_nair
Legend

@chrkohm,

It's default script shipping with Splunk installation. Unless you manually removed it after the installation, it should be there. 

Try a `find`

 find $SPLUNK_HOME -type f -name "external_lookup.py "

Alternatively you can download a fresh splunk installation and could copy from it

 

 

---
What goes around comes around. If it helps, hit it with Karma 🙂
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...