Splunk Dev

pulling Splunk Rest API in a python script

jmcclure8
New Member

I would like to pull the Splunk REST API jobs/$someSEARCH owner and use it as a variable in a python script
here is what I ahve so fare

def getAuthor(argvals, settings):
try:
namespace = settings.get("namespace", None)
sessionKey = settings['sessionKey']
ent = entity.getEntity('jobs', '| script python git', namespace=namespace, owner='nobody', sessionKey=sessionKey)
argvals ['author'] = ent['owner']
except Exception, e:
logger.error("Could not get the owner of the job. Error: %s" %(str(e)))
raise

logger.basicConfig(format='%(asctime)s %(levelname)s %(message)s', filename=os.path.join(os.environ['SPLUNK_HOME'],'var','log','splunk','git.log'), filemode='a+', level=logger.INFO)

keywords, argvals = splunk.Intersplunk.getKeywordsAndOptions()

em_message_fromArg = getarg(argvals, "message", "Commiting a with no message, please ask the owner about the change")

settings = splunk.Intersplunk.getOrganizedResults()

getAuthor(argvals, settings)

with open('/opt/splunk/etc/apps/incident_response/bin/test.txt', 'a') as file:
file.write(author)
What else could I do?

0 Karma
Get Updates on the Splunk Community!

Why You Can't Miss .conf25: Unleashing the Power of Agentic AI with Splunk & Cisco

The Defining Technology Movement of Our Lifetime The advent of agentic AI is arguably the defining technology ...

Deep Dive into Federated Analytics: Unlocking the Full Power of Your Security Data

In today’s complex digital landscape, security teams face increasing pressure to protect sprawling data across ...

Your summer travels continue with new course releases

Summer in the Northern hemisphere is in full swing, and is often a time to travel and explore. If your summer ...