Splunk Dev

Why am I getting this error "External search command 'File_Move1' returned error code 1" every time I run my python script?

Vipun
Explorer

• I am trying to execute python script File_Move1 using the search query |script File_Move1 but received the error below:
External search command 'File_Move1' returned error code 1.

• Please find my commands.conf details below in my C:\Program Files\Splunk\etc\system\local

[File_Move1]
chunked = true
filename = File_Move1.py
type = python

• I have placed the file in bin directory of C:\Program Files\Splunk\etc\apps\search\bin\scripts and C:\Program Files\Splunk\bin\scripts but still I receive that error
• I was able to execute the same script using Splunk cmd python File_Move.py using command prompt.

I kindly request you to look into it and guide me how to get rid of that error. I really appreciate your help on this.

Labels (1)

493669
Super Champion

Try running below:

< search query>| script python File_Move1.py 

Refer:https://answers.splunk.com/answers/62473/how-to-execute-external-script-to-manipulate-file-from-sear...

0 Karma

Vipun
Explorer

Hi,

Thank you for the help on this.

I have tried index="test" | script python File_Move1 or index="test" | script python File_Move1.py
earlier but still no luck. Could you please advise with any other fix.

highsplunker
Contributor

hi Vipun. i have the same error message -- i'm playing with Splunk REST API functionality now. i think you have to dig the script itself first.
in my case there was simply a syntactic error in my python code.
don't give up, good luck 🙂

0 Karma

Vipun
Explorer

Hi 493669,

I have followed that earlier but still, I get the same error

index="test" | script python File_Move1.py 

or

index="test" | script python File_Move1

⚠ External search command 'File_Move1' returned error code 1.
Please suggest any answers. Thank you for the help!!

Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...