I did * | geoip clientip
yet I get an error:
"External search command 'geoip' returned error code 1. First 1000 (of 9218) bytes of script output:" followed by the script output.
A screenshot is here:
You can do:
This will pipe all events in the index into the geoip tool.
answered 10 Dec '10, 21:04
Looks like you're getting an exception that splunk doesn't know how to parse. The main thing is it's returning failure (a nonzero exit code). You may want to capture from inside the script how it's being invoked and run it independently to investigate.
answered 15 Dec '10, 18:25