I have python script I want to add to the search app in splunk 5.0.3, I found some documentation: http://docs.splunk.com/Documentation/Splunk/5.0.3/Search/AddthecustomcommandtoSplunk
Now to make sure I am doing things correctly I copied the uniq.py and called it test.py and modified the commands.conf all in the $SPLUNK_HOME/etc/apps/search folder.
After restarting splunk I can see the script in: Manager > Advanced search > Search commands
However when I tried to use it I get an error:
Error in 'test' command: This command must be the first command of a search.
Meanwhile uniq work fine, obviously since that was built into splunk.
Thank you,
Brian
Ok I was able to get my custom python script to work however I needed to do the following:
[myscript]
external_cmd = myscript.py InputField OutputField
fields_list = InputField OutputField
{My Search} |lookup myscript InputField as SearchField |table OutputField
Thank you,
Brian
Ok I was able to get my custom python script to work however I needed to do the following:
[myscript]
external_cmd = myscript.py InputField OutputField
fields_list = InputField OutputField
{My Search} |lookup myscript InputField as SearchField |table OutputField
Thank you,
Brian
How are you calling the command? Your search should have a leading pipe and your command being the first command; something like:
| test
Yes, when I do {my search} | uniq I get my expected results however when I do {my search} | test I get:
Error in 'test' command: This command must be the first command of a search.