Splunk Dev

Question regarding SPLUNK_ARG_8/ Difficulty in writing python script for alert

Chinmai
Explorer

Hello Guys,

I have demo.csv file which is being continuously monitored, this file contains 3 fields namely servername, jobname and status.
This demo file is continuously being updated by another script.
Demo file contents are like this

servename,jobname,status
aaa, xyz1, success
bbb, xyz2, success
aaa, xyz3, fail.

Now i am monitoring the status of the jobs via splunk, so i have created a alert which will trigger and send a mail, whenever a job fails. The mail contains table format output of search query which has servename, jobname and status columns.

Now i am writing a python script which will be invoked by this alert along with the mail. So this python will update the status of respective job from "fail" to "success" in the demo.csv file.

But it seems my python script is not working, can anyone help me to write this python script?

Thanks in advance.

Tags (1)
0 Karma

mattymo
Splunk Employee
Splunk Employee

Splunk professional services would be glad to help you!! 😉
https://www.splunk.com/en_us/support-and-services/professional-services.html

Perhaps you can share your current code on github and someone might have a look?

In the meantime, I would recommend checking out some of the alert actions in splunkbase and reviewing their code as well as the alert action framework.

In your question you refer to the deprecated "run a script" alert actions, that still works, but you are much better off building for the alert action framework.

https://splunkbase.splunk.com/apps/#/app_content/alert_actions

http://docs.splunk.com/Documentation/Splunk/6.6.1/AdvancedDev/ModAlertsIntro
https://www.splunk.com/blog/2016/08/22/how-to-create-a-modular-alert.html
http://dev.splunk.com/view/dev-guide/SP-CAAAE7A

What you are trying to do sounds pretty simple...almost makes me wonder if an outputlookup or kvstore might not be easier?

- MattyMo
0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...