Call Splunk API to check logs

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
from requests.auth import HTTPBasicAuth
import json, pprint
import requests
from TestRailUtil import JSONObject
from types import SimpleNamespace
from datetime import datetime



base_url = 'https://xxxx:8089'
username = 'xxx'
password = 'xxx'


date1 = datetime.now()
print(date1)

search_query2 = "search=search RetailerTransID=\"XXX\" sourcetype=XXX host=PRODSQL earliest=-10d"
url= base_url+"/services/search/jobs/export?output_mode=raw"
r = requests.post(url, data=search_query2, auth=HTTPBasicAuth(username, password),
# headers = { 'Content-Type': 'application/json'},
verify = False)
date2 = datetime.now()
print(date2)
durating=date2-date1
print(r.status_code)
print(durating)

print(r.text) # if not found r.text==""
dic=dict()
index=r.text.index("retailersaleskey")
data_ls=r.text[index:].split(',')
for data in data_ls:
key=data.split("=")[0].strip()
value=data.split("=")[1].strip().replace("\"","")
dic[key]=value
retailersalesObj=json.loads(json.dumps(dic),object_hook=JSONObject)
print(retailersalesObj.retailersaleskey)
print(retailersalesObj.RetailerTransID)