Dashboards & Visualizations

Need help with a custom dashboard that calls external URLs to retrieve Mac_address attributes.

dadepu
Engager

Hi Splunkers,

I’m working on custom command script which should basically do the following:I need to create a dashboard where a customer enter a Mac_address and should get the attributes of the Mac_address (which are not available in the events).I have worked on a python script which will call the external URL’s to get the attributes of the Mac_address but I am unable to figure out what should be the next step. These are few doubts that I have
1) How can I send those Mac_address attributes to splunk as results?
2) Something like this in the search bar - | mycommand “xx:xx:xx:xx:xx:xx” (only one argument (Mac_address) at a time) this will be my full search query, is it possible?
So can anyone please let me know what the available options to get my desired outcome are? Is writing a custom command is good approach?

0 Karma

paramagurukarth
Builder

You can pass as normal argument

| YourCUstomCommand($entered_ip_address$)

And it will be available in sys.argv
Please go through the "Handling errors" in this link

I did this once, now forgot the exact syntax.. try | YourCUstomCommand $entered_ip_address$ if the above didn't worked

0 Karma

MuS
Legend

Hi dadepu,

there is an App already on Splunkbase https://splunkbase.splunk.com/app/1249/ 😉

cheers, MuS

woodcock
Esteemed Legend

You can use an external lookup (AK scripted lookup) like this:

| makeresults | eval Mac_Address=$Mac_Address$ | lookup YourExternalLookupHere MacAddress | fields - _time

http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Configureexternallookups

0 Karma
Get Updates on the Splunk Community!

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...