Splunk Search

key error in Python call to search results Json

Athildjax64
New Member

I have a custom action alert based on an App
The search is looking for a file, event, and file type. it then pipes the sha256 hash of the file out to ensure it is listed.
When I look for that field in the json I get a key error.

I am using
resp_dict = json.loads(sys.stdn.read())
resp_dict['sha256']
I have also tried
resp_dict["sha256"]
resp_dict['_sha256']

All attempts to print or write the contents of the search results json fail.

Tags (1)
0 Karma

damien_chillet
Builder

You wrote sys.stdn, but i assume it's just a typo?

0 Karma

Athildjax64
New Member

Yes that is a typo here, in the code it is sys.stdin.read()

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...