How to pass 'time' query to splunk enterprises using Splunk-Python SDK?2019 Community Moderator ElectionHow do I copy a file in Python?How can I safely create a nested directory in Python?How can I remove a trailing newline in Python?How do I parse a string to a float or int in Python?How to get the current time in PythonHow can I make a time delay in Python?How do I pass a variable by reference?How to get the number of elements in a list in Python?How to concatenate two lists in Python?How to lowercase a string in Python?
If curse and magic is two sides of the same coin, why the former is forbidden?
Instead of Universal Basic Income, why not Universal Basic NEEDS?
Professor being mistaken for a grad student
Why doesn't using two cd commands in bash script execute the second command?
How can I track script which gives me "command not found" right after the login?
If I can solve Sudoku can I solve Travelling Salesman Problem(TSP)? If yes, how?
Life insurance that covers only simultaneous/dual deaths
What approach do we need to follow for projects without a test environment?
Dice rolling probability game
Interplanetary conflict, some disease destroys the ability to understand or appreciate music
Is it true that good novels will automatically sell themselves on Amazon (and so on) and there is no need for one to waste time promoting?
PTIJ: Who should I vote for? (21st Knesset Edition)
How to explain that I do not want to visit a country due to personal safety concern?
How to create the Curved texte?
Welcoming 2019 Pi day: How to draw the letter π?
Can a druid choose the size of its wild shape beast?
A sequence that has integer values for prime indexes only:
Why did it take so long to abandon sail after steamships were demonstrated?
My Graph Theory Students
What is the significance behind "40 days" that often appears in the Bible?
If the DM rolls initiative once for a group of monsters, how do end-of-turn effects work?
Should we release the security issues we found in our product as CVE or we can just update those on weekly release notes?
Why doesn't the EU now just force the UK to choose between referendum and no-deal?
Co-worker team leader wants to inject his friend's awful software into our development. What should I say to our common boss?
How to pass 'time' query to splunk enterprises using Splunk-Python SDK?
2019 Community Moderator ElectionHow do I copy a file in Python?How can I safely create a nested directory in Python?How can I remove a trailing newline in Python?How do I parse a string to a float or int in Python?How to get the current time in PythonHow can I make a time delay in Python?How do I pass a variable by reference?How to get the number of elements in a list in Python?How to concatenate two lists in Python?How to lowercase a string in Python?
I am trying to pass query from Python(eclipse IDE) to extract data from
specific dashboard on SPLUNK enterprises. I am able to get data
printed on my console by passing the required queries however I am not
able to extract data for specific time interval(like if I want data
for 1 hour, 1 day, 1 week or 1 month)
I have tried commands like 'earliest', 'latest' along with my query but every time it throws an error stating "raise HTTPError(response) splunklib.binding.HTTPError: HTTP 400 Bad Request -- Search Factory: Unknown search command 'earliest'"
Here is my code
import splunklib.client as client
import splunklib.results as results
HOST = "my hostname"
PORT = 8089
USERNAME = "my username"
PASSWORD = "my password"
service = client.connect(
host=HOST,
port=PORT,
username=USERNAME,
password=PASSWORD)
rr = results.ResultsReader(service.jobs.export("search index=ccmjimmie | stats count(eval(resCode!=00200)) AS errored | chart sum(errored)|earliest=-1d"))
for result in rr:
if isinstance(result, results.Message):
# Diagnostic messages might be returned in the results
print(result.type, result.message)
elif isinstance(result, dict):
# Normal events are returned as dicts
print (result)
assert rr.is_preview == False
Output I am getting without using time query
OrderedDict([('sum(errored)', '1566')])
OrderedDict([('sum(errored)', '4404')])
OrderedDict([('sum(errored)', '6655')])
OrderedDict([('sum(errored)', '8992')])
etc...
This output is same as expected but not bounded by time. I want the same output but for Given Time Interval. And time interval should be passed from the search query "serch.jobs.export()" in the above Python code
Please let me know how do I pass 'time' query along with my required query.
Any help is most appreciated! Thanks in advance!
python python-requests splunk splunk-query
add a comment |
I am trying to pass query from Python(eclipse IDE) to extract data from
specific dashboard on SPLUNK enterprises. I am able to get data
printed on my console by passing the required queries however I am not
able to extract data for specific time interval(like if I want data
for 1 hour, 1 day, 1 week or 1 month)
I have tried commands like 'earliest', 'latest' along with my query but every time it throws an error stating "raise HTTPError(response) splunklib.binding.HTTPError: HTTP 400 Bad Request -- Search Factory: Unknown search command 'earliest'"
Here is my code
import splunklib.client as client
import splunklib.results as results
HOST = "my hostname"
PORT = 8089
USERNAME = "my username"
PASSWORD = "my password"
service = client.connect(
host=HOST,
port=PORT,
username=USERNAME,
password=PASSWORD)
rr = results.ResultsReader(service.jobs.export("search index=ccmjimmie | stats count(eval(resCode!=00200)) AS errored | chart sum(errored)|earliest=-1d"))
for result in rr:
if isinstance(result, results.Message):
# Diagnostic messages might be returned in the results
print(result.type, result.message)
elif isinstance(result, dict):
# Normal events are returned as dicts
print (result)
assert rr.is_preview == False
Output I am getting without using time query
OrderedDict([('sum(errored)', '1566')])
OrderedDict([('sum(errored)', '4404')])
OrderedDict([('sum(errored)', '6655')])
OrderedDict([('sum(errored)', '8992')])
etc...
This output is same as expected but not bounded by time. I want the same output but for Given Time Interval. And time interval should be passed from the search query "serch.jobs.export()" in the above Python code
Please let me know how do I pass 'time' query along with my required query.
Any help is most appreciated! Thanks in advance!
python python-requests splunk splunk-query
add a comment |
I am trying to pass query from Python(eclipse IDE) to extract data from
specific dashboard on SPLUNK enterprises. I am able to get data
printed on my console by passing the required queries however I am not
able to extract data for specific time interval(like if I want data
for 1 hour, 1 day, 1 week or 1 month)
I have tried commands like 'earliest', 'latest' along with my query but every time it throws an error stating "raise HTTPError(response) splunklib.binding.HTTPError: HTTP 400 Bad Request -- Search Factory: Unknown search command 'earliest'"
Here is my code
import splunklib.client as client
import splunklib.results as results
HOST = "my hostname"
PORT = 8089
USERNAME = "my username"
PASSWORD = "my password"
service = client.connect(
host=HOST,
port=PORT,
username=USERNAME,
password=PASSWORD)
rr = results.ResultsReader(service.jobs.export("search index=ccmjimmie | stats count(eval(resCode!=00200)) AS errored | chart sum(errored)|earliest=-1d"))
for result in rr:
if isinstance(result, results.Message):
# Diagnostic messages might be returned in the results
print(result.type, result.message)
elif isinstance(result, dict):
# Normal events are returned as dicts
print (result)
assert rr.is_preview == False
Output I am getting without using time query
OrderedDict([('sum(errored)', '1566')])
OrderedDict([('sum(errored)', '4404')])
OrderedDict([('sum(errored)', '6655')])
OrderedDict([('sum(errored)', '8992')])
etc...
This output is same as expected but not bounded by time. I want the same output but for Given Time Interval. And time interval should be passed from the search query "serch.jobs.export()" in the above Python code
Please let me know how do I pass 'time' query along with my required query.
Any help is most appreciated! Thanks in advance!
python python-requests splunk splunk-query
I am trying to pass query from Python(eclipse IDE) to extract data from
specific dashboard on SPLUNK enterprises. I am able to get data
printed on my console by passing the required queries however I am not
able to extract data for specific time interval(like if I want data
for 1 hour, 1 day, 1 week or 1 month)
I have tried commands like 'earliest', 'latest' along with my query but every time it throws an error stating "raise HTTPError(response) splunklib.binding.HTTPError: HTTP 400 Bad Request -- Search Factory: Unknown search command 'earliest'"
Here is my code
import splunklib.client as client
import splunklib.results as results
HOST = "my hostname"
PORT = 8089
USERNAME = "my username"
PASSWORD = "my password"
service = client.connect(
host=HOST,
port=PORT,
username=USERNAME,
password=PASSWORD)
rr = results.ResultsReader(service.jobs.export("search index=ccmjimmie | stats count(eval(resCode!=00200)) AS errored | chart sum(errored)|earliest=-1d"))
for result in rr:
if isinstance(result, results.Message):
# Diagnostic messages might be returned in the results
print(result.type, result.message)
elif isinstance(result, dict):
# Normal events are returned as dicts
print (result)
assert rr.is_preview == False
Output I am getting without using time query
OrderedDict([('sum(errored)', '1566')])
OrderedDict([('sum(errored)', '4404')])
OrderedDict([('sum(errored)', '6655')])
OrderedDict([('sum(errored)', '8992')])
etc...
This output is same as expected but not bounded by time. I want the same output but for Given Time Interval. And time interval should be passed from the search query "serch.jobs.export()" in the above Python code
Please let me know how do I pass 'time' query along with my required query.
Any help is most appreciated! Thanks in advance!
python python-requests splunk splunk-query
python python-requests splunk splunk-query
asked Mar 7 at 14:17
NagarjunKSNagarjunKS
62
62
add a comment |
add a comment |
1 Answer
1
active
oldest
votes
You have to put the earliest at the beginning of your search. Example for - 1 day until now:
"search index=ccmjimmie earliest=-1d | stats count(eval(resCode!=00200)) AS errored | chart sum(errored)"
Details see here: https://docs.splunk.com/Documentation/Splunk/7.2.4/SearchReference/SearchTimeModifiers
add a comment |
Your Answer
StackExchange.ifUsing("editor", function ()
StackExchange.using("externalEditor", function ()
StackExchange.using("snippets", function ()
StackExchange.snippets.init();
);
);
, "code-snippets");
StackExchange.ready(function()
var channelOptions =
tags: "".split(" "),
id: "1"
;
initTagRenderer("".split(" "), "".split(" "), channelOptions);
StackExchange.using("externalEditor", function()
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled)
StackExchange.using("snippets", function()
createEditor();
);
else
createEditor();
);
function createEditor()
StackExchange.prepareEditor(
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader:
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
,
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
);
);
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f55045957%2fhow-to-pass-time-query-to-splunk-enterprises-using-splunk-python-sdk%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
1 Answer
1
active
oldest
votes
1 Answer
1
active
oldest
votes
active
oldest
votes
active
oldest
votes
You have to put the earliest at the beginning of your search. Example for - 1 day until now:
"search index=ccmjimmie earliest=-1d | stats count(eval(resCode!=00200)) AS errored | chart sum(errored)"
Details see here: https://docs.splunk.com/Documentation/Splunk/7.2.4/SearchReference/SearchTimeModifiers
add a comment |
You have to put the earliest at the beginning of your search. Example for - 1 day until now:
"search index=ccmjimmie earliest=-1d | stats count(eval(resCode!=00200)) AS errored | chart sum(errored)"
Details see here: https://docs.splunk.com/Documentation/Splunk/7.2.4/SearchReference/SearchTimeModifiers
add a comment |
You have to put the earliest at the beginning of your search. Example for - 1 day until now:
"search index=ccmjimmie earliest=-1d | stats count(eval(resCode!=00200)) AS errored | chart sum(errored)"
Details see here: https://docs.splunk.com/Documentation/Splunk/7.2.4/SearchReference/SearchTimeModifiers
You have to put the earliest at the beginning of your search. Example for - 1 day until now:
"search index=ccmjimmie earliest=-1d | stats count(eval(resCode!=00200)) AS errored | chart sum(errored)"
Details see here: https://docs.splunk.com/Documentation/Splunk/7.2.4/SearchReference/SearchTimeModifiers
edited Mar 12 at 14:04
answered Mar 12 at 13:58
DaeronDaeron
468
468
add a comment |
add a comment |
Thanks for contributing an answer to Stack Overflow!
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
To learn more, see our tips on writing great answers.
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f55045957%2fhow-to-pass-time-query-to-splunk-enterprises-using-splunk-python-sdk%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown