Splunk Search

elasticsplunk convert to python3 not working- do you have an alternative suggestion?

jinnypt
Explorer

Hello.

Up to Splunk 7 version, it was python2, so I was using the app below to search elasticsearch.

https://github.com/brunotm/elasticsplunk

 

As I upgraded the Splunk version to 8 and started using python3, the app could not run.

So, I ask if there is a way to use this app.

* How to use it in python3? (If the conversion is successful and is in use, can you share it?)

* Is there an app that can replace it? (I'm not going to use the Elasticsearch Data Integrator - Modular Input app.)

* If there is an app you are using with splunk 8 (python3), please recommend it.

Labels (1)
0 Karma
1 Solution

jinnypt
Explorer

I solved it!

 

I added the path and file below.

 

$SPLUNK_HOME/etc/apps/{application_name}/local/server.conf

[general]

python.version = python2

View solution in original post

jinnypt
Explorer

Temporarily solved it with the method below.

 

$SPLUNK_HOME/etc/system/local/server.conf

[general]

python.version = python2

 

Since the above method runs in python2 for all apps, I think it will cause problems in the future.

Is there a way to run only a specific app with python2?

 

Entering the settings below doesn't work in python2.

$SPLUNK_HOME/etc/apps/{application_name}/local/app.conf

[install]

python.version = python2

0 Karma

jinnypt
Explorer

I solved it!

 

I added the path and file below.

 

$SPLUNK_HOME/etc/apps/{application_name}/local/server.conf

[general]

python.version = python2

splunkcol
Builder

@jinnypt 

Hello,

I have noticed that the Elasticsplunk app no longer exists https://splunkbase.splunk.com/app/3493 I do not know if you know what the reason is or if it was updated by another APP I would appreciate if you could inform me.

At this moment I need to use that APP or the one that allows me to use the query with the "ess" command.

If possible it would help me a lot which are the configuration files that I have to modify both on splunk and Elasticsearch side.

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...