AppInspect reports failure with splunk-sdk: Some 'search/*' endpoints has been deprecated in Splunk 9.0.1
Shows how to fix appInspect reports failure with splunk-sdk: Some 'search/*' endpoints has been deprecated in Splunk 9.0.1. Use it when you hit this exact problem. Skip it when your error message or symptom looks different.
TL;DR
For "FAILURE: Some 'search/' endpoints has been deprecated in Splunk 9.0.1 and replaced by new v2 APIs": vendored the Splunk Python SDK into a Splunk app and ran splunk-appinspect, which fails with: "FAILURE: Some 'search/' endpoints has been deprecated in Splunk 9.0.1 and replaced by new v2 APIs", pointing at lib/splunklib/client.py line 578.
FAILURE: Some 'search/*' endpoints has been deprecated in Splunk 9.0.1 and replaced by new v2 APIsSteps
- Vendored the Splunk Python SDK into a Splunk app and ran splunk-appinspect, which fails with: "FAILURE: Some 'search/*' endpoints has been deprecated in Splunk 9.0.1 and replaced by new v2 APIs", pointing at lib/splunklib/client.py line 578. Same failure showed up with splunk-sdk 1.7.4 and 2.0.2. The vendored copy of splunklib in the app had been hand-edited (imports changed from
from splunklib importto relativefrom . import, trailing newlines added), so it no longer matched the SDK files AppInspect allowlists. AppInspect only skips the check when the vendored files are byte-identical to the SDK on GitHub.
- The check is AppInspect's, not the SDK's, and it passes only for pristine SDK files. Diff your vendored splunklib against the SDK source on GitHub (e.g.
git diffon the vendored client.py), then replace the whole splunklib directory with an exact copy from the SDK repo and make sure imports sayfrom splunklib import ...rather than relative imports. Two separate reporters confirmed the failure disappeared once their vendored copy was byte-identical to the one on GitHub, and closed their issues and support tickets on that resolution.
When to use
You are seeing this: Same failure showed up with splunk-sdk 1.7.4 and 2.0.2. Use this skill when you run into "AppInspect reports failure with splunk-sdk: Some 'search/*' endpoints has been deprecated in Splunk 9.0.1".
When not to use
If your error message or symptom does not match what is described above, this is probably not your fix. Search for your exact error text instead of forcing this one to fit.
Versions
Versions mentioned in the source: Splunk 9.0.1, splunk-sdk 1.7.4, 2.0.2. If you are on something much newer or older, the details may have shifted.
Why this happens
The original report does not dig into a root cause. It documents the symptom and the fix that resolved it.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.