Splunk Dev

When using the Python-SDK, why is Splunk silently returning nothing for some indices?

haffi112
New Member

I'm trying to use the Python SDK to search in Splunk.

However, I can only search on some indices, for others I just get an empty response.

For example, when I use the command

search index=trace

I get a response, but when I use

search index=read

I don't get any response. But if I use the web interface this query works, i.e. my user has rights to search on that index and I am authenticating myself when using the Python-SDK.

Do you have any idea what could explain this? The silent returning of nothing is not helping me.

0 Karma

haffi112
New Member

I have confirmed with an administrator that it is not a problem with access rights as the script shows the same behavior when he authenticates with his user.

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.0.2 Availability: On cloud and On-premise!

A few months ago, we released Splunk Enterprise Security 8.0 for our cloud customers. Today, we are excited to ...

Logs to Metrics

Logs and Metrics Logs are generally unstructured text or structured events emitted by applications and written ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...