All Posts

Find Answers
Ask questions. Get answers. Find technical product solutions from passionate members of the Splunk community.

All Posts

Traceback Part-2 08-02-2023 16:15:01.641 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserve... See more...
Traceback Part-2 08-02-2023 16:15:01.641 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: rv = PersistentServerConnectionApplicationServer._load_file(filename) 08-02-2023 16:15:01.641 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: File "/opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py", line 57, in _load_file 08-02-2023 16:15:01.641 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: m = imp.load_module(munged_name, filehandle, filename, data) 08-02-2023 16:15:01.641 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: File "/opt/splunk/lib/python3.7/imp.py", line 234, in load_module 08-02-2023 16:15:01.641 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: return load_source(name, filename, file) 08-02-2023 16:15:01.641 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: File "/opt/splunk/lib/python3.7/imp.py", line 171, in load_source 08-02-2023 16:15:01.641 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: module = _load(spec) 08-02-2023 16:15:01.641 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: File "<frozen importlib._bootstrap>", line 696, in _load 08-02-2023 16:15:01.641 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: File "<frozen importlib._bootstrap>", line 677, in _load_unlocked 08-02-2023 16:15:01.641 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: File "<frozen importlib._bootstrap_external>", line 728, in exec_module 08-02-2023 16:15:01.641 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: File "<frozen importlib._bootstrap>", line 219, in _call_with_frames_removed 08-02-2023 16:15:01.641 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: File "/opt/splunk/etc/apps/CustomApp/bin/umbrella_dashboard_api_client.py", line 13, in <module> 08-02-2023 16:15:01.641 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: from logger import Logger 08-02-2023 16:15:01.641 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: ModuleNotFoundError: No module named 'logger' 08-02-2023 16:15:01.806 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py:2: DeprecationWarning: the imp module is deprecated in favour of importlib; see the module's documentation for alternative uses 08-02-2023 16:15:01.806 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: import imp 08-02-2023 16:15:01.808 +0530 ERROR HttpListener [77650 TcpChannelThread] - Exception while processing request from 127.0.0.1:37198 for /en-US/splunkd/__raw/servicesNS/nobody/CustomApp/umbrella?type=dns&from=1690929026000&to=1690972226000&_=1690972792547: Error starting: No module named 'logger' 08-02-2023 16:15:02.059 +0530 WARN PersistentScript [77745 PersistentScriptIo] - Process {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: PID 78587 exited with code 1 08-02-2023 16:15:02.059 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: Traceback (most recent call last): 08-02-2023 16:15:02.059 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: File "/opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py", line 114, in <module> 08-02-2023 16:15:02.059 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: h.run() 08-02-2023 16:15:02.059 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: File "/opt/splunk/lib/python3.7/site-packages/splunk/persistconn/packet.py", line 191, in run 08-02-2023 16:15:02.059 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: self.handle_packet(in_packet) 08-02-2023 16:15:02.059 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: File "/opt/splunk/lib/python3.7/site-packages/splunk/persistconn/handle_loop.py", line 36, in handle_packet 08-02-2023 16:15:02.060 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: self._current_handler = self.load(in_packet.command, in_packet.command_arg, in_packet.allow_stream()) 08-02-2023 16:15:02.060 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: File "/opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py", line 22, in load 08-02-2023 16:15:02.060 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: class_and_meths = self._get_class_and_methods(command[0], stream_allowed) 08-02-2023 16:15:02.060 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: File "/opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py", line 31, in _get_class_and_methods 08-02-2023 16:15:02.060 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: meths = self._cached_load_file(filename) 08-02-2023 16:15:02.060 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: File "/opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py", line 42, in _cached_load_file 08-02-2023 16:15:02.060 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: rv = PersistentServerConnectionApplicationServer._load_file(filename) 08-02-2023 16:15:02.060 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: File "/opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py", line 57, in _load_file 08-02-2023 16:15:02.060 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: m = imp.load_module(munged_name, filehandle, filename, data) 08-02-2023 16:15:02.060 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: File "/opt/splunk/lib/python3.7/imp.py", line 234, in load_module 08-02-2023 16:15:02.060 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: return load_source(name, filename, file) 08-02-2023 16:15:02.060 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: File "/opt/splunk/lib/python3.7/imp.py", line 171, in load_source 08-02-2023 16:15:02.060 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: module = _load(spec) 08-02-2023 16:15:02.060 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: File "<frozen importlib._bootstrap>", line 696, in _load 08-02-2023 16:15:02.060 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: File "<frozen importlib._bootstrap>", line 677, in _load_unlocked 08-02-2023 16:15:02.060 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: File "<frozen importlib._bootstrap_external>", line 728, in exec_module 08-02-2023 16:15:02.060 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: File "<frozen importlib._bootstrap>", line 219, in _call_with_frames_removed 08-02-2023 16:15:02.060 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: File "/opt/splunk/etc/apps/CustomApp/bin/umbrella_dashboard_api_client.py", line 13, in <module> 08-02-2023 16:15:02.060 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: from logger import Logger 08-02-2023 16:15:02.060 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: ModuleNotFoundError: No module named 'logger'
Traceback Part-1 08-02-2023 16:15:01.256 +0530 ERROR HttpListener [77650 TcpChannelThread] - Exception while processing request from 127.0.0.1:43332 for /en-US/splunkd/__raw/servicesNS/nobody/Custom... See more...
Traceback Part-1 08-02-2023 16:15:01.256 +0530 ERROR HttpListener [77650 TcpChannelThread] - Exception while processing request from 127.0.0.1:43332 for /en-US/splunkd/__raw/servicesNS/nobody/CustomApp/umbrella?type=dns&from=1690929026000&to=1690972226000&_=1690972792543: Error starting: No module named 'logger' 08-02-2023 16:15:01.493 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py:2: DeprecationWarning: the imp module is deprecated in favour of importlib; see the module's documentation for alternative uses 08-02-2023 16:15:01.493 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: import imp 08-02-2023 16:15:01.493 +0530 WARN PersistentScript [77745 PersistentScriptIo] - Process {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: PID 78576 exited with code 1 08-02-2023 16:15:01.493 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: Traceback (most recent call last): 08-02-2023 16:15:01.494 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: File "/opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py", line 114, in <module> 08-02-2023 16:15:01.494 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: h.run() 08-02-2023 16:15:01.494 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: File "/opt/splunk/lib/python3.7/site-packages/splunk/persistconn/packet.py", line 191, in run 08-02-2023 16:15:01.494 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: self.handle_packet(in_packet) 08-02-2023 16:15:01.494 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: File "/opt/splunk/lib/python3.7/site-packages/splunk/persistconn/handle_loop.py", line 36, in handle_packet 08-02-2023 16:15:01.494 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: self._current_handler = self.load(in_packet.command, in_packet.command_arg, in_packet.allow_stream()) 08-02-2023 16:15:01.494 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: File "/opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py", line 22, in load 08-02-2023 16:15:01.494 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: class_and_meths = self._get_class_and_methods(command[0], stream_allowed) 08-02-2023 16:15:01.494 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: File "/opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py", line 31, in _get_class_and_methods 08-02-2023 16:15:01.494 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: meths = self._cached_load_file(filename) 08-02-2023 16:15:01.494 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: File "/opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py", line 42, in _cached_load_file 08-02-2023 16:15:01.494 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: rv = PersistentServerConnectionApplicationServer._load_file(filename) 08-02-2023 16:15:01.494 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: File "/opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py", line 57, in _load_file 08-02-2023 16:15:01.494 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: m = imp.load_module(munged_name, filehandle, filename, data) 08-02-2023 16:15:01.494 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: File "/opt/splunk/lib/python3.7/imp.py", line 234, in load_module 08-02-2023 16:15:01.494 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: return load_source(name, filename, file) 08-02-2023 16:15:01.494 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: File "/opt/splunk/lib/python3.7/imp.py", line 171, in load_source 08-02-2023 16:15:01.494 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: module = _load(spec) 08-02-2023 16:15:01.494 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: File "<frozen importlib._bootstrap>", line 696, in _load 08-02-2023 16:15:01.494 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: File "<frozen importlib._bootstrap>", line 677, in _load_unlocked 08-02-2023 16:15:01.494 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: File "<frozen importlib._bootstrap_external>", line 728, in exec_module 08-02-2023 16:15:01.494 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: File "<frozen importlib._bootstrap>", line 219, in _call_with_frames_removed 08-02-2023 16:15:01.494 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: File "/opt/splunk/etc/apps/CustomApp/bin/umbrella_dashboard_api_client.py", line 13, in <module> 08-02-2023 16:15:01.494 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: from logger import Logger 08-02-2023 16:15:01.494 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: ModuleNotFoundError: No module named 'logger' 08-02-2023 16:15:01.494 +0530 ERROR HttpListener [77650 TcpChannelThread] - Exception while processing request from 127.0.0.1:37186 for /en-US/splunkd/__raw/servicesNS/nobody/CustomApp/umbrella?type=dns&from=1690929026000&to=1690972226000&_=1690972792546: Error starting: No module named 'logger' 08-02-2023 16:15:01.641 +0530 WARN PersistentScript [77745 PersistentScriptIo] - Process {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: PID 78582 exited with code 1 08-02-2023 16:15:01.641 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: Traceback (most recent call last): 08-02-2023 16:15:01.641 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: File "/opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py", line 114, in <module> 08-02-2023 16:15:01.641 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: h.run() 08-02-2023 16:15:01.641 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: File "/opt/splunk/lib/python3.7/site-packages/splunk/persistconn/packet.py", line 191, in run 08-02-2023 16:15:01.641 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: self.handle_packet(in_packet) 08-02-2023 16:15:01.641 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: File "/opt/splunk/lib/python3.7/site-packages/splunk/persistconn/handle_loop.py", line 36, in handle_packet 08-02-2023 16:15:01.641 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: self._current_handler = self.load(in_packet.command, in_packet.command_arg, in_packet.allow_stream()) 08-02-2023 16:15:01.641 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: File "/opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py", line 22, in load 08-02-2023 16:15:01.641 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: class_and_meths = self._get_class_and_methods(command[0], stream_allowed) 08-02-2023 16:15:01.641 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: File "/opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py", line 31, in _get_class_and_methods 08-02-2023 16:15:01.641 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: meths = self._cached_load_file(filename) 08-02-2023 16:15:01.641 +0530 ERROR PersistentScript [77745 PersistentScriptIo] - From {/opt/splunk/bin/python3.7 /opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py}: File "/opt/splunk/lib/python3.7/site-packages/splunk/persistconn/appserver.py", line 42, in _cached_load_file  
@VatsalJagani  yes we are getting a full trace back, Its from our 3rd party app.        
The product_brand token already holds the chosen values. You can use the prefix, suffix, valuePrefix, valueSuffix and delimiter options to determine how the token is formatted. Simple XML Reference... See more...
The product_brand token already holds the chosen values. You can use the prefix, suffix, valuePrefix, valueSuffix and delimiter options to determine how the token is formatted. Simple XML Reference - Splunk Documentation
@danielbb - What do you mean by a couple of environments? You need to check in the environment/SearchHead which is generating this error for you. And there has to be automatic lookup. If you don't s... See more...
@danielbb - What do you mean by a couple of environments? You need to check in the environment/SearchHead which is generating this error for you. And there has to be automatic lookup. If you don't see it try to find it inside props.conf from the backend.  
Adding to @yuanliu 's remark - one more thing about the matching logic. Remember that "key!=value" condition is not the same as "NOT key=value" condition. The "key!=value" condition will match only ... See more...
Adding to @yuanliu 's remark - one more thing about the matching logic. Remember that "key!=value" condition is not the same as "NOT key=value" condition. The "key!=value" condition will match only events having the key called "key" which have values not matching "value". But the "NOT key=value" will do that but also match all events where the key called "key" is not present at all.
You can only send HEC (or s2s embedded in HTML) to your Cloud HEC inputs. So in order to ingest syslog you need to have something in place on-premise to receive the syslogs and push it as something t... See more...
You can only send HEC (or s2s embedded in HTML) to your Cloud HEC inputs. So in order to ingest syslog you need to have something in place on-premise to receive the syslogs and push it as something that Cloud will accept. That can be a UF as @gcusello suggested or a SC4S or properly configured rsyslog/syslog-ng instance with HTTP output.
While I wholeheartedly agree with the "don't use regex for structured data" it's worth noting that sometimes it's not easy to extract the structured part from the whole event.
I am running a search in JavaScript that returns results similar to this one.   new SearchManager({ id: "my_search", results: true, search: ` | makeresults count=10 ... See more...
I am running a search in JavaScript that returns results similar to this one.   new SearchManager({ id: "my_search", results: true, search: ` | makeresults count=10 | streamstats count | fields - _time ` });   What I would like to obtain is a JS array with the resulting vector in a variable. I tried to solve it like so:   let search = mvc.Components.get("my_search"); let results = search.data("results"); results_outside = results.on("data", function(){ // 1b) let rows = results.data().rows; let array = rows.flat(1); // I want the flattened array, no nested one console.log("array: ", array); tokens.set("arrays", array); // 2) return array; // 1a) }); console.log("results_outside: ", results_outside);    The `array` variable within the function has the desired results, as I can tell from the console. However exporting it to the global scope neighter works by:   1) storing it in `results_outside` - this will have the same value as results.   or   2) setting it to a token.
OK. Assuming that: 1. You always have a drive letter at the beginning 2. You don't have "empty parts" (you don't have consecutive backslashes which are syntactically correct if you want to specify ... See more...
OK. Assuming that: 1. You always have a drive letter at the beginning 2. You don't have "empty parts" (you don't have consecutive backslashes which are syntactically correct if you want to specify a file path but are typically not returned as a path to existing file) 3. You want to extract the part after the first four components The regex to do so would be like that: [a-zA-Z]:\\\\([^\\]+\\){4}(?<remainder>.*) The "remainder" capture group will capture the path after first four directories. Of course if you want to do it with "rex" command in Splunk, you need to escape all backslashes which makes it something like this: | rex  "[a-zA-Z]:\\\\\\\\([^\\\\]+\\\\){4}(?<remainder>.*)"
I have "Product Brand" multiselect filter in a Splunk dashboard. It is a dynamic filter rather than static. I also have a panel displaying all product brands. Now, I want another conditional panel to... See more...
I have "Product Brand" multiselect filter in a Splunk dashboard. It is a dynamic filter rather than static. I also have a panel displaying all product brands. Now, I want another conditional panel to display further information of 3 of the brands in the product brand list if user selects any of these 3.  I know I have to set a <change> and <condition> tag in XML to toggle between the display of panel and store the selected values. I now write three condition tags with set token like this:    <change> <condition match="A"> <set token="show_product_panel">true</set> <set token="show_product">$value$</set> </condition> <condition value="B"> <set token="show_product_panel">true</set> <set token="show_product">$value$</set> </condition> <condition value="C"> <set token="show_product_panel">true</set> <set token="show_product">$value$</set> </condition> <condition> <unset token="show_product_panel"></unset> <unset token="show_product"></unset> </condition> </change>   However, I want the $show_product$ to hold multiple values instead of one, as it is a multiselect filter. How should I do so? I have tried something in each of the condition like but won't work. How can I "append" the values into $show_product$? Thanks.   <eval token="show_product">if(isnull($show_product$), $value$, $show_product$.", ".$value$)</eval>     FYI: the $show_product$ will be passed into the conditional panel like this   <row depends="$show_product_panel$"> <panel> <chart> <search> <query>index IN ("A_a", "A_b") | where match(index, "A_" + $subsidiary$) | dedup id sortby _time | eval "Product Brand" = coalesce('someFieldA', 'someFieldB') | search "Product Brand" IN ($show_product$) | timechart span=1mon count by "Product Brand"</query> <earliest>$field1.earliest$</earliest> <latest>$field1.latest$</latest> </search> <option name="charting.chart">column</option> <option name="charting.drilldown">none</option> <option name="refresh.display">progressbar</option> </chart> </panel> </row>     FYI: Product Brand XML code snippet:   <input type="multiselect" token="product_brand" searchWhenChanged="true"> <label>Product Brand</label> <fieldForLabel>brand_combine</fieldForLabel> <fieldForValue>brand_combine</fieldForValue> <search> <query>index IN ("A","B") | eval brand_combine = coalesce('someFieldA','someFieldB') | search brand_combine != null | where match(index, "zendesk_ticket_" + $subsidiary$) | dedup brand_combine | fields brand_combine</query> <earliest>0</earliest> <latest></latest> </search> <choice value="*">All</choice> <default>*</default> <initialValue>*</initialValue> <delimiter>,</delimiter> <change> <condition match="A"> <set token="show_product_panel">true</set> <set token="show_product">$value$</set> </condition> <condition value="B"> <set token="show_product_panel">true</set> <set token="show_product">$value$</set> </condition> <condition value="C"> <set token="show_product_panel">true</set> <set token="show_product">$value$</set> </condition> <condition> <unset token="show_product_panel"></unset> <unset token="show_product"></unset> </condition> </change> </input>  
The "Forwarding and Receiving" settings menu section is just a simplified version of specifying a default target group in outputs.conf. For a more complicated setup (like selectively forwarding event... See more...
The "Forwarding and Receiving" settings menu section is just a simplified version of specifying a default target group in outputs.conf. For a more complicated setup (like selectively forwarding events from single indexes or sets of indexes to specific receivers) you need to configure that in configs manually (it involves more than just defining outputs - it requires assigning proper metadata in props/transforms) - see the link provided by @gcusello .
Hi @Adpafer, yes, you can, following the instructions on the above url. Ciao. Giuseppe
Yes, that's a feature, not a bug But seriously, Splunk internally stores and processes time as a so-called "unix timestamp" which contains number of seconds since midnight Jan 1st 1970. That time... See more...
Yes, that's a feature, not a bug But seriously, Splunk internally stores and processes time as a so-called "unix timestamp" which contains number of seconds since midnight Jan 1st 1970. That timestamp does not change regardless of where the users is located an what timezone the user has set in his preferences. But the timezone is rendered according to user's preferences-set timezone. Which means that the same _time field from the event (or any other field on which you do strftime() or format) will be rendered differently for different users. Furthermore, the timerange selections are interpreted according to your local user's timezone which means that @d will mean something different depending on whether it's CET, BST, EST or whatever you can come up with. As far as I remember, there is no support for specifying a timezone definition directly in a timerange specification parameters so you need to "cheat". One possible walkaround (but a bit ugly I admit)is to use a subsearch (possibly packed into a macro) to render a timestamp in your local timezone, cut the timezone part, then append the given timezone spec and then parse the time string back to unix timestamp to get your earliest/latest value as integer. Very very ugly but it should work.
Hi Indexer can forward logs to other servers (forwarding and receiving)and I have to configure IP nad port of the host to which indexer can forward logs. I have two hosts visible in GUI (Forwardi... See more...
Hi Indexer can forward logs to other servers (forwarding and receiving)and I have to configure IP nad port of the host to which indexer can forward logs. I have two hosts visible in GUI (Forwarding and Receiving): serverA:portA serverB:portB The problem is that I do not want to send all logs to these hosts. I want to send logs from IndexA to hostA  and logs from IndexB to hostB. Can I do it or I cannot ? If yes, how? Thanks and regards, pawel  
How do we disable the mouse over items (Inspect, FullScreen, Refresh) in a dashboard studio dashboard? We would like to disable it, because it overlays other information on our dashboard and it is s... See more...
How do we disable the mouse over items (Inspect, FullScreen, Refresh) in a dashboard studio dashboard? We would like to disable it, because it overlays other information on our dashboard and it is stuck if we click on an item on the page (not disappearing when moving the mouse to another item). The mouse was hovering over "WSSP", but the mouse over item on "ARTAS-TTF3" is still visible, because that was the last clicked item.
Hi Neeraj That metric is an overall global metric for all queries that gives you what it states. Time spent doing Executions for all queries in the Database. What I would suggest is to speak to t... See more...
Hi Neeraj That metric is an overall global metric for all queries that gives you what it states. Time spent doing Executions for all queries in the Database. What I would suggest is to speak to the DBA, and have them create you a custom query which you can run under custom metrics foreach DB, which can possibly exclude this specific query to give you a value that you can use in the health rule. Ciao
You should be a bit more specific about what columns you're talking about. If you're talking about the timeline view above the events list on the search screen, the resolution of that timeline is aut... See more...
You should be a bit more specific about what columns you're talking about. If you're talking about the timeline view above the events list on the search screen, the resolution of that timeline is automatic and you can't change it.
Hi Is the "old data" just on disk and left back when you start to use a new servers or is it frozen data? r. Ismo
By "saved search" I mean that the used searches in the Dasboard are all "ds.savedSearch", which are updated by a cron schedule. So i would expect loading results from previously executed searches. B... See more...
By "saved search" I mean that the used searches in the Dasboard are all "ds.savedSearch", which are updated by a cron schedule. So i would expect loading results from previously executed searches. Browser is Firefox 102.10.0esr and also with an up to date Chrome we see the same issue. And by SVGs we are talking about simple boxes with a Text.