Hi,
I have created an scripted lookup (app) that looks up data in MongoDB and returns some results.
I have used an existing lookup (that works) as a template.
When I test my lookup from the console with
~/bin/splunk cmd python lookup.py < input.csv
it works (just as the other script that I used as a base), however, when searching from splunk it returns no result:
app.conf
[ui]
is_visible = false
label = MongoLookup
transforms.conf
[mlookup]
external_cmd = lookup.py
fields_list = clientuid country cref refid
Searching with:
index="idx_XXXXXX" sourcetype="YYYYYYY" | lookup mlookup clientuid as userID | table userID, country
I get no results for country,cref,refid
Is there a way I could see what's splunk doing when calling my script?
... View more