Installation

Python script execution from Splunk GUI

manish_singh_77
Builder

Hi Team,

We have a python script which runs and executes the results of the knowledge objects of rest apis. We are going to run this script on adhoc basis which will modify and list the permissions. Do we have to use custom search command for that?

If yes then please let us know the approach...

Tags (1)
0 Karma

manjunathmeti
Champion

You can create a custom alert action to trigger python script using steps provided here:

https://answers.splunk.com/answers/810829/problem-with-scripted-alert.html#answer-810832

And use sendalert command to trigger script.

<base search> | sendalert scriptcustomalert
0 Karma

manish_singh_77
Builder

@manjunathmeti ,

I have a python script, for now I am executing the commands from the server and getting the results.

For example: /opt/splunk/bin/splunk cmd python /home/splunk/test_Script.py list savedsearch --user test_user

This will return the results once executed from the server, how we do the same thing from GUI?

0 Karma

manjunathmeti
Champion

If you want to run a script as command and get results in search app then you need to create a custom search command. Check this:

https://dev.splunk.com/enterprise/docs/developapps/customsearchcommands/createcustomsearchcmd

If you listing all saved searches, you can use below search query:

| rest /servicesNS/-/-/saved/searches  | table title,cron_schedule,next_scheduled_time,eai:acl.owner,actions,eai:acl.app
0 Karma

manish_singh_77
Builder

@manjunathmeti

Thanks for your reply, slight correction from my end, we can also use curl utility to modify the permissions, right?

0 Karma

manjunathmeti
Champion

If you are asking about modifying the splunk objects (like savedsearches, views etc.) permissions using REST API calls using curl utility, then yes you can use that.

Check this link:
https://docs.splunk.com/Documentation/Splunk/8.0.3/RESTTUT/RESTbasicexamples

0 Karma

manish_singh_77
Builder

@manjunathmeti

Do you have any sample python script?

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...