Refine your search:

I've been tinkering with a custom search command that uses win32com.client. When I try to invoke my search command I get the following error

(-2147352567, 'Exception occurred.', (0, None, None, None, 0, -2147200925), None)

I've tried to call the offending section using the bundled interpreter, and it works just fine.

./splunk cmd python

Any ideas I'm kinda stumped. I really don't want to have my search command, exec an external interpreter.

== Update == I've implemented another version that execs a vbs script to invoke the win32 com component. It also fails which leads me to believe that splunkd is doing something funny.

asked 26 Sep '11, 05:51

Marinus's gravatar image

accept rate: 40%

edited 27 Sep '11, 05:32

2 Answers:

Running splunk under a normal user account solves the problem. On Windows splunk cmd python doesn't run in the same context as the service.


answered 10 Oct '11, 03:28

Marinus's gravatar image

accept rate: 40%

I would follow sys.stderr Not logging to splunkd on Splunk Answers

I have been having issues with trying to find errors with custom commands and the link above has an answer which explains how to add logging information to your script so you can try to track where it is producing errors or how far it is going.


answered 27 Sep '11, 13:11

Drainy's gravatar image

accept rate: 26%

I am able to trap the error. The issue is what the splunkd process does to the environment that causes the python interpreter to behave differently.

(28 Sep '11, 01:28) Marinus
Post your answer
toggle preview

Follow this question

Log In to enable email subscriptions



Answers + Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text]( "Title")
  • image?![alt text](/path/img.jpg "Title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported



Asked: 26 Sep '11, 05:51

Seen: 1,097 times

Last updated: 10 Oct '11, 03:28

Copyright © 2005-2014 Splunk Inc. All rights reserved.