How to pass 'time' query to splunk enterprises using Splunk-Python SDK?2019 Community Moderator ElectionHow do I copy a file in Python?How can I safely create a nested directory in Python?How can I remove a trailing newline in Python?How do I parse a string to a float or int in Python?How to get the current time in PythonHow can I make a time delay in Python?How do I pass a variable by reference?How to get the number of elements in a list in Python?How to concatenate two lists in Python?How to lowercase a string in Python?

If curse and magic is two sides of the same coin, why the former is forbidden?

Instead of Universal Basic Income, why not Universal Basic NEEDS?

Professor being mistaken for a grad student

Why doesn't using two cd commands in bash script execute the second command?

How can I track script which gives me "command not found" right after the login?

If I can solve Sudoku can I solve Travelling Salesman Problem(TSP)? If yes, how?

Life insurance that covers only simultaneous/dual deaths

What approach do we need to follow for projects without a test environment?

Dice rolling probability game

Interplanetary conflict, some disease destroys the ability to understand or appreciate music

Is it true that good novels will automatically sell themselves on Amazon (and so on) and there is no need for one to waste time promoting?

PTIJ: Who should I vote for? (21st Knesset Edition)

How to explain that I do not want to visit a country due to personal safety concern?

How to create the Curved texte?

Welcoming 2019 Pi day: How to draw the letter π?

Can a druid choose the size of its wild shape beast?

A sequence that has integer values for prime indexes only:

Why did it take so long to abandon sail after steamships were demonstrated?

My Graph Theory Students

What is the significance behind "40 days" that often appears in the Bible?

If the DM rolls initiative once for a group of monsters, how do end-of-turn effects work?

Should we release the security issues we found in our product as CVE or we can just update those on weekly release notes?

Why doesn't the EU now just force the UK to choose between referendum and no-deal?

Co-worker team leader wants to inject his friend's awful software into our development. What should I say to our common boss?



How to pass 'time' query to splunk enterprises using Splunk-Python SDK?



2019 Community Moderator ElectionHow do I copy a file in Python?How can I safely create a nested directory in Python?How can I remove a trailing newline in Python?How do I parse a string to a float or int in Python?How to get the current time in PythonHow can I make a time delay in Python?How do I pass a variable by reference?How to get the number of elements in a list in Python?How to concatenate two lists in Python?How to lowercase a string in Python?










1
















I am trying to pass query from Python(eclipse IDE) to extract data from
specific dashboard on SPLUNK enterprises. I am able to get data
printed on my console by passing the required queries however I am not
able to extract data for specific time interval(like if I want data
for 1 hour, 1 day, 1 week or 1 month)




I have tried commands like 'earliest', 'latest' along with my query but every time it throws an error stating "raise HTTPError(response) splunklib.binding.HTTPError: HTTP 400 Bad Request -- Search Factory: Unknown search command 'earliest'"



Here is my code



import splunklib.client as client
import splunklib.results as results


HOST = "my hostname"
PORT = 8089
USERNAME = "my username"
PASSWORD = "my password"
service = client.connect(
host=HOST,
port=PORT,
username=USERNAME,
password=PASSWORD)
rr = results.ResultsReader(service.jobs.export("search index=ccmjimmie | stats count(eval(resCode!=00200)) AS errored | chart sum(errored)|earliest=-1d"))

for result in rr:
if isinstance(result, results.Message):
# Diagnostic messages might be returned in the results
print(result.type, result.message)
elif isinstance(result, dict):
# Normal events are returned as dicts
print (result)
assert rr.is_preview == False


Output I am getting without using time query



OrderedDict([('sum(errored)', '1566')])
OrderedDict([('sum(errored)', '4404')])
OrderedDict([('sum(errored)', '6655')])
OrderedDict([('sum(errored)', '8992')])
etc...


This output is same as expected but not bounded by time. I want the same output but for Given Time Interval. And time interval should be passed from the search query "serch.jobs.export()" in the above Python code



Please let me know how do I pass 'time' query along with my required query.



Any help is most appreciated! Thanks in advance!










share|improve this question


























    1
















    I am trying to pass query from Python(eclipse IDE) to extract data from
    specific dashboard on SPLUNK enterprises. I am able to get data
    printed on my console by passing the required queries however I am not
    able to extract data for specific time interval(like if I want data
    for 1 hour, 1 day, 1 week or 1 month)




    I have tried commands like 'earliest', 'latest' along with my query but every time it throws an error stating "raise HTTPError(response) splunklib.binding.HTTPError: HTTP 400 Bad Request -- Search Factory: Unknown search command 'earliest'"



    Here is my code



    import splunklib.client as client
    import splunklib.results as results


    HOST = "my hostname"
    PORT = 8089
    USERNAME = "my username"
    PASSWORD = "my password"
    service = client.connect(
    host=HOST,
    port=PORT,
    username=USERNAME,
    password=PASSWORD)
    rr = results.ResultsReader(service.jobs.export("search index=ccmjimmie | stats count(eval(resCode!=00200)) AS errored | chart sum(errored)|earliest=-1d"))

    for result in rr:
    if isinstance(result, results.Message):
    # Diagnostic messages might be returned in the results
    print(result.type, result.message)
    elif isinstance(result, dict):
    # Normal events are returned as dicts
    print (result)
    assert rr.is_preview == False


    Output I am getting without using time query



    OrderedDict([('sum(errored)', '1566')])
    OrderedDict([('sum(errored)', '4404')])
    OrderedDict([('sum(errored)', '6655')])
    OrderedDict([('sum(errored)', '8992')])
    etc...


    This output is same as expected but not bounded by time. I want the same output but for Given Time Interval. And time interval should be passed from the search query "serch.jobs.export()" in the above Python code



    Please let me know how do I pass 'time' query along with my required query.



    Any help is most appreciated! Thanks in advance!










    share|improve this question
























      1












      1








      1









      I am trying to pass query from Python(eclipse IDE) to extract data from
      specific dashboard on SPLUNK enterprises. I am able to get data
      printed on my console by passing the required queries however I am not
      able to extract data for specific time interval(like if I want data
      for 1 hour, 1 day, 1 week or 1 month)




      I have tried commands like 'earliest', 'latest' along with my query but every time it throws an error stating "raise HTTPError(response) splunklib.binding.HTTPError: HTTP 400 Bad Request -- Search Factory: Unknown search command 'earliest'"



      Here is my code



      import splunklib.client as client
      import splunklib.results as results


      HOST = "my hostname"
      PORT = 8089
      USERNAME = "my username"
      PASSWORD = "my password"
      service = client.connect(
      host=HOST,
      port=PORT,
      username=USERNAME,
      password=PASSWORD)
      rr = results.ResultsReader(service.jobs.export("search index=ccmjimmie | stats count(eval(resCode!=00200)) AS errored | chart sum(errored)|earliest=-1d"))

      for result in rr:
      if isinstance(result, results.Message):
      # Diagnostic messages might be returned in the results
      print(result.type, result.message)
      elif isinstance(result, dict):
      # Normal events are returned as dicts
      print (result)
      assert rr.is_preview == False


      Output I am getting without using time query



      OrderedDict([('sum(errored)', '1566')])
      OrderedDict([('sum(errored)', '4404')])
      OrderedDict([('sum(errored)', '6655')])
      OrderedDict([('sum(errored)', '8992')])
      etc...


      This output is same as expected but not bounded by time. I want the same output but for Given Time Interval. And time interval should be passed from the search query "serch.jobs.export()" in the above Python code



      Please let me know how do I pass 'time' query along with my required query.



      Any help is most appreciated! Thanks in advance!










      share|improve this question















      I am trying to pass query from Python(eclipse IDE) to extract data from
      specific dashboard on SPLUNK enterprises. I am able to get data
      printed on my console by passing the required queries however I am not
      able to extract data for specific time interval(like if I want data
      for 1 hour, 1 day, 1 week or 1 month)




      I have tried commands like 'earliest', 'latest' along with my query but every time it throws an error stating "raise HTTPError(response) splunklib.binding.HTTPError: HTTP 400 Bad Request -- Search Factory: Unknown search command 'earliest'"



      Here is my code



      import splunklib.client as client
      import splunklib.results as results


      HOST = "my hostname"
      PORT = 8089
      USERNAME = "my username"
      PASSWORD = "my password"
      service = client.connect(
      host=HOST,
      port=PORT,
      username=USERNAME,
      password=PASSWORD)
      rr = results.ResultsReader(service.jobs.export("search index=ccmjimmie | stats count(eval(resCode!=00200)) AS errored | chart sum(errored)|earliest=-1d"))

      for result in rr:
      if isinstance(result, results.Message):
      # Diagnostic messages might be returned in the results
      print(result.type, result.message)
      elif isinstance(result, dict):
      # Normal events are returned as dicts
      print (result)
      assert rr.is_preview == False


      Output I am getting without using time query



      OrderedDict([('sum(errored)', '1566')])
      OrderedDict([('sum(errored)', '4404')])
      OrderedDict([('sum(errored)', '6655')])
      OrderedDict([('sum(errored)', '8992')])
      etc...


      This output is same as expected but not bounded by time. I want the same output but for Given Time Interval. And time interval should be passed from the search query "serch.jobs.export()" in the above Python code



      Please let me know how do I pass 'time' query along with my required query.



      Any help is most appreciated! Thanks in advance!







      python python-requests splunk splunk-query






      share|improve this question













      share|improve this question











      share|improve this question




      share|improve this question










      asked Mar 7 at 14:17









      NagarjunKSNagarjunKS

      62




      62






















          1 Answer
          1






          active

          oldest

          votes


















          0














          You have to put the earliest at the beginning of your search. Example for - 1 day until now:



          "search index=ccmjimmie earliest=-1d | stats count(eval(resCode!=00200)) AS errored | chart sum(errored)"



          Details see here: https://docs.splunk.com/Documentation/Splunk/7.2.4/SearchReference/SearchTimeModifiers






          share|improve this answer
























            Your Answer






            StackExchange.ifUsing("editor", function ()
            StackExchange.using("externalEditor", function ()
            StackExchange.using("snippets", function ()
            StackExchange.snippets.init();
            );
            );
            , "code-snippets");

            StackExchange.ready(function()
            var channelOptions =
            tags: "".split(" "),
            id: "1"
            ;
            initTagRenderer("".split(" "), "".split(" "), channelOptions);

            StackExchange.using("externalEditor", function()
            // Have to fire editor after snippets, if snippets enabled
            if (StackExchange.settings.snippets.snippetsEnabled)
            StackExchange.using("snippets", function()
            createEditor();
            );

            else
            createEditor();

            );

            function createEditor()
            StackExchange.prepareEditor(
            heartbeatType: 'answer',
            autoActivateHeartbeat: false,
            convertImagesToLinks: true,
            noModals: true,
            showLowRepImageUploadWarning: true,
            reputationToPostImages: 10,
            bindNavPrevention: true,
            postfix: "",
            imageUploader:
            brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
            contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
            allowUrls: true
            ,
            onDemand: true,
            discardSelector: ".discard-answer"
            ,immediatelyShowMarkdownHelp:true
            );



            );













            draft saved

            draft discarded


















            StackExchange.ready(
            function ()
            StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f55045957%2fhow-to-pass-time-query-to-splunk-enterprises-using-splunk-python-sdk%23new-answer', 'question_page');

            );

            Post as a guest















            Required, but never shown

























            1 Answer
            1






            active

            oldest

            votes








            1 Answer
            1






            active

            oldest

            votes









            active

            oldest

            votes






            active

            oldest

            votes









            0














            You have to put the earliest at the beginning of your search. Example for - 1 day until now:



            "search index=ccmjimmie earliest=-1d | stats count(eval(resCode!=00200)) AS errored | chart sum(errored)"



            Details see here: https://docs.splunk.com/Documentation/Splunk/7.2.4/SearchReference/SearchTimeModifiers






            share|improve this answer





























              0














              You have to put the earliest at the beginning of your search. Example for - 1 day until now:



              "search index=ccmjimmie earliest=-1d | stats count(eval(resCode!=00200)) AS errored | chart sum(errored)"



              Details see here: https://docs.splunk.com/Documentation/Splunk/7.2.4/SearchReference/SearchTimeModifiers






              share|improve this answer



























                0












                0








                0







                You have to put the earliest at the beginning of your search. Example for - 1 day until now:



                "search index=ccmjimmie earliest=-1d | stats count(eval(resCode!=00200)) AS errored | chart sum(errored)"



                Details see here: https://docs.splunk.com/Documentation/Splunk/7.2.4/SearchReference/SearchTimeModifiers






                share|improve this answer















                You have to put the earliest at the beginning of your search. Example for - 1 day until now:



                "search index=ccmjimmie earliest=-1d | stats count(eval(resCode!=00200)) AS errored | chart sum(errored)"



                Details see here: https://docs.splunk.com/Documentation/Splunk/7.2.4/SearchReference/SearchTimeModifiers







                share|improve this answer














                share|improve this answer



                share|improve this answer








                edited Mar 12 at 14:04

























                answered Mar 12 at 13:58









                DaeronDaeron

                468




                468





























                    draft saved

                    draft discarded
















































                    Thanks for contributing an answer to Stack Overflow!


                    • Please be sure to answer the question. Provide details and share your research!

                    But avoid


                    • Asking for help, clarification, or responding to other answers.

                    • Making statements based on opinion; back them up with references or personal experience.

                    To learn more, see our tips on writing great answers.




                    draft saved


                    draft discarded














                    StackExchange.ready(
                    function ()
                    StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f55045957%2fhow-to-pass-time-query-to-splunk-enterprises-using-splunk-python-sdk%23new-answer', 'question_page');

                    );

                    Post as a guest















                    Required, but never shown





















































                    Required, but never shown














                    Required, but never shown












                    Required, but never shown







                    Required, but never shown

































                    Required, but never shown














                    Required, but never shown












                    Required, but never shown







                    Required, but never shown







                    Popular posts from this blog

                    Thal And Out Agency railway station See also References External links Navigation menuOfficial Web Site of Pakistan RailwaysArchivedOfficial Web Site of Pakistan Railwayseeexpanding ite

                    Understanding generators in Python2019 Community Moderator ElectionGenerator function not working pythonFor loop not executing two timesGenerators - Printing generated valuesWhy can a python generator only be used once?What exactly do generators do?What does the “yield” keyword do?What does “list comprehension” mean? How does it work and how can I use it?sklearn Kfold acces single fold instead of for loopIs a generator the callable? Which is the generator?Apply Border To Range Of Cells Using OpenpyxlCalling an external command in PythonWhat are metaclasses in Python?What is the difference between @staticmethod and @classmethod?Finding the index of an item given a list containing it in PythonDifference between append vs. extend list methods in PythonHow can I safely create a nested directory in Python?Does Python have a ternary conditional operator?Understanding slice notationUnderstanding Python super() with __init__() methodsDoes Python have a string 'contains' substring method?

                    How can I change the color of pagination dots of UIPageControl?How to change UIPageControl dotsIs there a way to change page indicator dots colorCustomize dot with image of UIPageControl at index 0 of UIPageControlNo visible @interface for 'NSObject<PageControlDelegate>' declares the selector 'pageControlPageDidChange:'How to change the color of pagination dots in UIPageControl with a different color per pagepagecontrol indicator custom image instead of DefaultChanging the colour of UIPageControl dots in MonoTouchpagecontrol selectable page visibility color?Alternative way to load ViewControllers on a UIPageControlHow to set only layer.border-color for UIpage control dots in swiftHow can I develop for iPhone using a Windows development machine?How to change the name of an iOS app?UITableView - change section header coloruipagecontrol indicator(dot)issueCustom UIPageControl dots color not changingchange the interspace between UIPageControl dotsHow to change Status Bar text color in iOSHow can I change image tintColor in iOS and WatchKitUIPageControl dots with larger space in between each dotsHow to change the color of pagination dots in UIPageControl with a different color per page