Splunk Search

key error in Python call to search results Json

Athildjax64
New Member

I have a custom action alert based on an App
The search is looking for a file, event, and file type. it then pipes the sha256 hash of the file out to ensure it is listed.
When I look for that field in the json I get a key error.

I am using
resp_dict = json.loads(sys.stdn.read())
resp_dict['sha256']
I have also tried
resp_dict["sha256"]
resp_dict['_sha256']

All attempts to print or write the contents of the search results json fail.

Tags (1)
0 Karma

damien_chillet
Builder

You wrote sys.stdn, but i assume it's just a typo?

0 Karma

Athildjax64
New Member

Yes that is a typo here, in the code it is sys.stdin.read()

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...